VOL IV · Nº 207FRIDAY · MAY 15 · 20261 FLAG OPEN
The RFPRoom Quarterly
Pinegate Software · published by uStack
RFP-2031 · Security

Q-2031-S08 — How is MFA enforced?

Status Approved. Reviewer: Diego Ortega.

Approved answer
Approved by Diego Ortega on May 14, 2026 5:56 PM.

MFA is mandatory for all internal accounts (TOTP, FIDO2/WebAuthn). Customer admins can enforce workspace-wide MFA; WebAuthn (Yubikey, Touch ID) is supported alongside TOTP and is required for super-admin actions.

Question metadata
Category: Security
Status: Approved
Drafts: 1
Reviews: 1
Draft history (1)
Every authored version, source library link, and the snippet citations attached.
  • v1Approvedmatched LIB-SEC-022May 16, 2026 5:56 PM

    MFA is mandatory for all internal accounts (TOTP, FIDO2/WebAuthn). Customer admins can enforce workspace-wide MFA; WebAuthn (Yubikey, Touch ID) is supported alongside TOTP and is required for super-admin actions.

    Rationale: AI-matched against LIB-SEC-022; reviewed verbatim.

Reviewer decisions (1)
Sign-offs and rationale per reviewer.
  • Diego Ortegasecurity_reviewerApprovedMay 13, 2026 5:56 PM

    Verified against trust portal documentation; no changes.

Acting as Nina Vega · VP salesswitch role →