⚡ 06hr : 00min : 00sec

Services

Digital Explore Assets Explore Business Explore Footprint Protection Explore
Products How it works About Docs Careers Resources Contact
Sign in Get started
Docs › Getting Started › Email Verification, Security & Unified Profile
🔒 Security Standards

Email Verification, Security & Unified Profile

Learn how Coderyx protects enterprise workspaces using mandatory email verification gates, step-up security for sensitive transactions, and a single cross-product profile synchronization architecture.

Coderyx Zero-Trust Verification Lifecycle Defense in Depth
Gate 1: Registration

Account created with secure salted hashing. Platform remains locked until email token verified.

Gate 2: SSO Token Handshake

Internal products verify email verification status before granting access tickets.

Gate 3: Step-Up Auth

Sensitive actions (cancel sub, change password, MFA) require password re-confirmation.

1. Mandatory Email Verification

To defend against malicious bot registration, credential stuffing, and unvetted footprint scanning, all users must verify their email address before they can perform any platform actions:

2. Step-Up Password Confirmation

In accordance with modern zero-trust enterprise security (NIST SP 800-63B), Coderyx requires step-up authentication for high-impact and irreversible operations. Even if an active browser session exists, you must re-enter your password to execute:

⚠️ Session Timeout: Once step-up confirmation is satisfied, your authorization is cached for 3 hours (auth.password_timeout). After 3 hours, attempting a sensitive operation prompts a fresh confirmation modal.

3. Unified Profile Picture Synchronization

Coderyx enforces a single cross-product profile picture policy:

How 1 Avatar Runs Across All Products:

  1. User uploads photo in Central Dashboard (/dashboard/profile). Supported: JPG, PNG, WEBP up to 2MB.
  2. Central stores the image in secure public storage (/storage/avatars/{hash}.webp).
  3. Central synchronously updates the avatar column in LeadFlow ERP (coderyx_erpgo.users) and Guard (coderyx.users).
  4. SSO ticket payloads deliver the resolved avatar_url upon every product launch.
  5. In LeadFlow, the avatar renders in Team Chat Spaces (current user dot, message bubbles, DM lists, member rosters).
  6. In ProtoStudio, the avatar renders in project header collaborator circles and live review comments.

4. Multi-Factor Authentication (MFA)

You can secure your account using Time-based One-Time Passwords (TOTP) compatible with Google Authenticator, Microsoft Authenticator, 1Password, or Yubico:

  1. Navigate to Dashboard → Profile → Security.
  2. Click Enable Multi-Factor Authentication.
  3. Confirm your password (step-up verification).
  4. Scan the QR code with your authenticator app and enter the 6-digit confirmation code.
  5. Save your 8 emergency backup codes in a secure location.

5. Active Sessions & Device Audit

View all active devices currently authenticated to your account under Security Settings:

← Return to Dashboard Need Help? Contact Engineers →