MFA CONTINUITY INVENTORY

Know what breaks before an authenticator is gone

Map the accounts, multi-factor authentication (MFA) devices, and recovery codes your company depends on.

14 DAY FREE TRIAL · NO CREDIT CARD REQUIRED

Made and hosted in EU
All data stored in the EU
KMS wrapped encryption keys
No TOTP seeds stored
00  THE PROBLEM

Your IdP and password manager only see part of MFA.

Okta and Entra cover federated apps. Your password vault stores secrets. Neither tells you which bank portal, registrar, root account, founder account, or vendor portal depends on a specific phone or security key.

01

Unmanaged accounts sit outside reports

Root accounts, registrars, banks, vendor portals, and founder accounts rarely live in the same identity report. The map exists in memory, chat, and old tickets.

02

A password vault is not an MFA map

Your vault stores secrets. It does not tell you what a lost YubiKey unlocks, or which services depend on one phone.

03

Offboarding leaves blind spots

A departing employee may hold the only authenticator for accounts the company owns. Revoking access before you transfer MFA can create the outage you were trying to avoid.


01  WHAT IT DOES

Accounts, authenticators, recovery codes, and evidence in one inventory.

ACCOUNTS & ENROLLMENTS

Every account, with the authenticators assigned to it.

Add the services that matter outside your identity provider and see which authenticators protect each one. One account can have several authenticators, and one authenticator can protect many accounts.

  • Unlimited accounts, authenticators, and assignments
  • Best practice default: 2 MFA devices per domain, adjustable
  • Clear status: protected, one device risk, or no 2FA yet
  • Record upstream identity providers and SSO chains
RECOVERY CODES

Recovery codes without shared TOTP seeds.

RecoveryCodes stores recovery codes for a domain. It does not store TOTP seeds or generate shared login codes, so it is an inventory and emergency record, not another team authenticator app.

  • Codes stay separate from the password vault
  • Share selected domains with approved workspace members
  • Every reveal requires step-up authentication and audit logging
DEVICES & REVERSE LOOKUPS

Replacing security key 1? These are the 14 accounts to enroll again.

Each authenticator has a name, kind, owner, and optional physical location. When a phone, hardware key, or backup phone leaves service, you get the exact list of accounts to fix before you disable it.

  • Personal authenticators for one person, shared authenticators for the whole team
  • Reverse lookup: every account an authenticator protects, in one click
02  THE AUDIT

Evidence for the accounts your IdP cannot report.

Security reviews and ISO 27001 audits ask how you manage MFA outside the identity provider. What protects each account? What happens when someone leaves? Where do recovery codes live, and who accessed them? Export inventory and audit evidence instead of assembling it from memory.

01

MFA coverage report

Every account, its 2FA status, and every authenticator enrolled on it. The concise answer to "show us your MFA coverage."

02

One device risks

Accounts protected by only one authenticator. No account should be one lost phone away from a lockout.

03

Offboarding attestation

Every authenticator a departing user held and every account it was enrolled on. Proof that access was transferred before the account was removed.

04

Access and change log

A log of who viewed recovery codes, changed enrollments, updated devices, or shared access to a domain. The raw trail behind every report.


03  TRUST

How the recovery material is protected.

Recovery codes can bypass MFA, so the product has to be explicit about what it stores, what it does not store, and what you can take with you.

01

Envelope encryption per code

Recovery code values are encrypted with per code data keys. Those keys are wrapped by KMS infrastructure in the EU.

02

No TOTP seed vault

RecoveryCodes records which authenticators protect which accounts. It does not hold TOTP seeds or act as a shared code generator.

03

Continuity and export

Export the inventory and audit evidence as JSON from the dashboard. Recovery code values stay view only behind step-up authentication, so the emergency story is explicit rather than implied.

04

Fresh sign in for sensitive actions

Viewing a recovery code, changing an assignment, or deactivating a user requires fresh authentication. Anything that could weaken your security asks for proof it is you.

SIGNING IN

Access to the tool is protected the same way.

Start in seconds with social login and passkeys. When you are ready to centralize identity, organization SSO is available.

All plans

Social login & passkeys

Sign in with Google, GitHub, or GitLab. Or use a passkey on every device.

Google GitHub GitLab Passkey login Face ID / Touch ID Hardware key
Compliance Enterprise

Organization SSO

Connect OIDC on Compliance. Enterprise customers can discuss SAML, SCIM, or LDAP requirements.

OIDC SAML SCIM LDAP

04  PRICING

Pricing by capability.

Operational, evidentiary, contractual. 14 day free trial. No credit card required.

Inventory
49 € 39 € / month
Billed annually
Everything operational: see your exposure and stop improvising.
Get started
  • Unlimited account and authenticator inventory
  • Reverse lookup for every authenticator
  • Track recovery codes per domain
  • Status labels: protected, one device risk, no 2FA
  • Social login & passkey login
  • Authenticator ownership tracking
  • Workspace with member roles
  • Domain and authenticator sharing across the workspace
  • Coverage and risk report as an in-app view
  • Audit log (90 days)
Enterprise
Let's talk
Custom contract
Everything contractual: security, deployment, and policy terms.
Contact us
  • Everything in Compliance, plus
  • Customer managed encryption keys through KMS
  • SAML, SCIM, and LDAP enforcement
  • Self hosting option
  • Defined SLA
  • Custom data retention policies

All prices exclude tax.

When an authenticator changes, know what to fix.

Start mapping the accounts your IdP cannot explain, the authenticators that protect them, and the recovery codes that get you back in.