Security, privacy and audit requirements · C0889
Does AuroraMed enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity?
In the pilot (v0.2.0, synthetic data)
Short answer
The system must enforce session binding, idle timeouts, walk-away lock and single concurrent session per identity. That is REQ-2252, a top-priority requirement for all three tiers. The pilot covers part of this. The rest is designed, not built. What v0.2.0 does today: Idle lock screen, session list/revoke, partial-session gating; no device binding and no single-session rule. Test in the specification: second concurrent session is denied.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2252
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed authenticate workforce with FIDO2 hardware key plus badge (or PIN plus badge) and phishing-resistant flows? Pilot
- Does AuroraMed integrate with directory services via SAML/OIDC/LDAP/SCIM for provisioning where a customer has one? Designed
- Does AuroraMed support badge tap-and-go (NFC/UWB) authentication and CCOW-style context sharing? Designed
See it in context: Identity, authentication and single sign-on · Search the help center · Ask a question