2FA is a requirement for client logins. We support TOTP apps, WebAuthn/passkeys, and backup codes for resilience.
We design secure enrollment, device management, and recovery to minimize lockouts while maintaining strong posture.
Visit Two-Factor Authentication (2FA) →
How We Use It
- Enhanced account security for user logins
- TOTP and WebAuthn/passkey support
- Secure backup code and recovery flows
Auth & Security
Why this matters: Security is trust—modern auth and session practices protect users and keep compliance teams comfortable. Security is foundational. We standardize on modern auth, strong session management, and defense-in-depth controls to protect users and systems. Preferred defaults: BetterAuth for app auth, token-based sessions with rotation, 2FA (TOTP + WebAuthn), Arcjet for edge protection.