TR-02 / TRUST

Identity & access

Passwords, passkeys, devices, sessions, invitations and administrative access controls.

01 / TR-02

Controlled sign-in

Connect combines Argon2id-processed passwords with short-lived access tokens, rotating refresh sessions and FIDO2/WebAuthn security keys.

Device revocation ends related sessions and push subscriptions. On the next eligible sign-in path, the client removes account-scoped local data including history, ratchet state, outbox, prekeys and device identity; this cannot physically erase an endpoint that remains offline or compromised.

  • Token reuse revokes the affected family
  • Devices and sessions are visible and revocable
  • Login history supports operational review
02 / TR-02

Enterprise boundary

Multi-tenancy, SSO and SCIM provisioning are not currently claimed public product capabilities. Organisational processes for joining, role changes and departure must be defined before each controlled release.

CONTROLLED ESCALATION

Review the claim independently.

Review the Evidence Center, documentation and operational status together.

Evidence Center