Know what breaks before an authenticator is gone
Map the accounts, multi-factor authentication (MFA) devices, and recovery codes your company depends on.
14 DAY FREE TRIAL · NO CREDIT CARD REQUIRED
Your IdP and password manager only see part of MFA.
Okta and Entra cover federated apps. Your password vault stores secrets. Neither tells you which bank portal, registrar, root account, founder account, or vendor portal depends on a specific phone or security key.
Unmanaged accounts sit outside reports
Root accounts, registrars, banks, vendor portals, and founder accounts rarely live in the same identity report. The map exists in memory, chat, and old tickets.
A password vault is not an MFA map
Your vault stores secrets. It does not tell you what a lost YubiKey unlocks, or which services depend on one phone.
Offboarding leaves blind spots
A departing employee may hold the only authenticator for accounts the company owns. Revoking access before you transfer MFA can create the outage you were trying to avoid.
Accounts, authenticators, recovery codes, and evidence in one inventory.
Every account, with the authenticators assigned to it.
Add the services that matter outside your identity provider and see which authenticators protect each one. One account can have several authenticators, and one authenticator can protect many accounts.
- ✓ Unlimited accounts, authenticators, and assignments
- ✓ Best practice default: 2 MFA devices per domain, adjustable
- ✓ Clear status: protected, one device risk, or no 2FA yet
- ✓ Record upstream identity providers and SSO chains
Recovery codes without shared TOTP seeds.
RecoveryCodes stores recovery codes for a domain. It does not store TOTP seeds or generate shared login codes, so it is an inventory and emergency record, not another team authenticator app.
- ✓ Codes stay separate from the password vault
- ✓ Share selected domains with approved workspace members
- ✓ Every reveal requires step-up authentication and audit logging
Replacing security key 1? These are the 14 accounts to enroll again.
Each authenticator has a name, kind, owner, and optional physical location. When a phone, hardware key, or backup phone leaves service, you get the exact list of accounts to fix before you disable it.
- ✓ Personal authenticators for one person, shared authenticators for the whole team
- ✓ Reverse lookup: every account an authenticator protects, in one click
Evidence for the accounts your IdP cannot report.
Security reviews and ISO 27001 audits ask how you manage MFA outside the identity provider. What protects each account? What happens when someone leaves? Where do recovery codes live, and who accessed them? Export inventory and audit evidence instead of assembling it from memory.
MFA coverage report
Every account, its 2FA status, and every authenticator enrolled on it. The concise answer to "show us your MFA coverage."
One device risks
Accounts protected by only one authenticator. No account should be one lost phone away from a lockout.
Offboarding attestation
Every authenticator a departing user held and every account it was enrolled on. Proof that access was transferred before the account was removed.
Access and change log
A log of who viewed recovery codes, changed enrollments, updated devices, or shared access to a domain. The raw trail behind every report.
How the recovery material is protected.
Recovery codes can bypass MFA, so the product has to be explicit about what it stores, what it does not store, and what you can take with you.
Envelope encryption per code
Recovery code values are encrypted with per code data keys. Those keys are wrapped by KMS infrastructure in the EU.
No TOTP seed vault
RecoveryCodes records which authenticators protect which accounts. It does not hold TOTP seeds or act as a shared code generator.
Continuity and export
Export the inventory and audit evidence as JSON from the dashboard. Recovery code values stay view only behind step-up authentication, so the emergency story is explicit rather than implied.
Fresh sign in for sensitive actions
Viewing a recovery code, changing an assignment, or deactivating a user requires fresh authentication. Anything that could weaken your security asks for proof it is you.
Access to the tool is protected the same way.
Start in seconds with social login and passkeys. When you are ready to centralize identity, organization SSO is available.
Social login & passkeys
Sign in with Google, GitHub, or GitLab. Or use a passkey on every device.
Organization SSO
Connect OIDC on Compliance. Enterprise customers can discuss SAML, SCIM, or LDAP requirements.
Pricing by capability.
Operational, evidentiary, contractual. 14 day free trial. No credit card required.
- ✓ Unlimited account and authenticator inventory
- ✓ Reverse lookup for every authenticator
- ✓ Track recovery codes per domain
- ✓ Status labels: protected, one device risk, no 2FA
- ✓ Social login & passkey login
- ✓ Authenticator ownership tracking
- ✓ Workspace with member roles
- ✓ Domain and authenticator sharing across the workspace
- ✓ Coverage and risk report as an in-app view
- ✓ Audit log (90 days)
- Everything in Inventory, plus
- ✓ Dated, exportable offboarding attestation
- ✓ Dated, exportable coverage and risk reports
- ✓ Extended audit retention
- ✓ Offboarding workflow before access is removed
- ✓ OIDC SSO
- SOON
- ✓ Email and webhook alerts for risks and sensitive access
- Everything in Compliance, plus
- ✓ Customer managed encryption keys through KMS
- ✓ SAML, SCIM, and LDAP enforcement
- ✓ Self hosting option
- ✓ Defined SLA
- ✓ Custom data retention policies
All prices exclude tax.
When an authenticator changes, know what to fix.
Start mapping the accounts your IdP cannot explain, the authenticators that protect them, and the recovery codes that get you back in.