Security and trust
MFA and authentication
Sign-in, sessions, email verification, and optional MFA.
- Audience
- All users
- Plan availability
- All plans
- Last reviewed
Cyber Health Score supports email and password sign-in with server-side sessions, email verification, password reset, and optional multi-factor authentication (MFA).
Authentication features
- email and password sign-in
- email verification before dashboard access
- password reset with session invalidation after reset
- optional TOTP-based MFA using an authenticator app
- backup codes for MFA recovery
Enabling MFA
- Sign in to your workspace.
- Open Settings and go to Security (or personal security settings).
- Start MFA setup and scan the QR code with your authenticator app.
- Enter the verification code to confirm setup.
- Store your backup codes securely.
Sign-in with MFA enabled
When MFA is enabled, sign-in requires your password and a valid authenticator code (or a backup code). This is enforced in the sign-in flow, not only as a visual indicator after login.
Session behaviour
Sessions expire after inactivity according to product policy. Signing out ends your current session. Sensitive changes such as password reset invalidate existing sessions.
Expected result
You understand how to protect your account with MFA and what verification steps apply before workspace access.
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation