TR-02 / TRUST

Identity & access

Passwords, passkeys, devices, sessions, invitations and administrative access controls.

01 / TR-02

Controlled sign-in

Connect combines Argon2id-processed passwords with short-lived access tokens, rotating refresh sessions and FIDO2/WebAuthn security keys.

  • Token reuse revokes the affected family
  • Devices and sessions are visible and revocable
  • Login history supports operational review
02 / TR-02

Enterprise boundary

Multi-tenancy, SSO and SCIM provisioning are not currently claimed public product capabilities. Organisational processes for joining, role changes and departure must be defined during a pilot.

CONTROLLED ESCALATION

Review the claim independently.

Review the Evidence Center, documentation and operational status together.

Evidence Center