Security and two-factor authentication
The VoraSuite security posture as a customer sees it: protected sign in, optional two-factor authentication, per site data isolation, permission gated access and the record trail.
VoraSuite is built so that everyday security does not depend on anyone remembering to be careful. Sign in is protected, access is permission gated, data is isolated per site, and changes to governed records leave a trail. This guide covers the posture as you experience it inside the product.
Sign in protection
The login page carries an automated abuse check that challenges suspicious traffic before a sign in attempt reaches your account, and repeated failed attempts are rate limited. Accounts are created through verified email flows: every added team member proves ownership of their address through a setup link before the account is usable.
Two-factor authentication
Any user can add two-factor authentication to their own account from the Account page at /access/account. Setup takes a minute: press Set up two-factor authentication, scan the QR code with an authenticator app such as Google Authenticator, 1Password or Microsoft Authenticator, and confirm the 6 digit code. From then on sign in asks for a current code as well as the password. Removing it later requires a verified two-factor session, so a stolen password alone cannot switch it off.
Protection inside the workspace
- Per site data isolation: the records of each site are scoped apart, and access is granted per site.
- Permission gated access: every action checks a specific permission, enforced on the server, not just hidden in the interface.
- The record trail: changes to governed records are logged with who acted and when, which is the same trail VoraAudit draws on.
- Seat and access management: administrators can deactivate a user at any time from the Team page, ending their access immediately.
Good password practice
Use a unique password for VoraSuite, ideally from a password manager, and turn on two-factor authentication, especially for administrator accounts. Never share a cockpit account between people; shared sign ins belong only on the floor kiosks, which are designed for it.
The public /security and /trust pages describe the platform side: infrastructure, data handling and operational practices. This article covers what you control from inside the product.
Still stuck? Get support or contact the team. Support replies personally, typically within one business day.