Security, privacy and audit requirements · C0888
Does AuroraMed authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. In the pilot: TOTP MFA (RFC 6238) with recovery codes for T7+ roles; no FIDO2/badge. For reference, REQ-2251 (a top-priority requirement, all three tiers) says the system must authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows. Check: sMS OTP is not offered.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2251
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity? Pilot
- Does AuroraMed integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one? Designed
See it in context: Identity, authentication and single sign-on · Search the help center · Ask a question