Security settings
- MFA: TOTP with recovery codes; organisation enforcement applies to pages and every mutation; sensitive operations require a verified session.
- SSO: SAML 2.0 (metadata URL/XML) or OIDC (Entra ID, Google Workspace, Keycloak, WorkOS); verified domains (DNS TXT), JIT provisioning, role mapping from groups/claims, enforced SSO, password login disabled per domain. SCIM is prepared behind the API token layer.
- Approvals: two-person rule for awareness changes, reportability reversals, evidence deletion, submission amendments, owner/admin role changes, secret rotation, legal-hold release.
- Auditor access: time-limited (≤ 180 days), scoped, read-only, fully logged.
- Data & retention: retention categories, full organisation export (JSON, audit CSV, integrity manifest, evidence index), organisation deletion with 30-day cooling-off, owner-only, MFA-verified, with a description of what remains for legal reasons.
Last updated . This page describes the current release.