Can I set up Two-Factor Authentication (2FA) for specific customers in Rocketlane?
No, Rocketlane doesn't currently offer a direct way to enable 2FA for individual customers or specific projects out of the box. 2FA is generally configured at a broader account level if available.
How secure are the "magic links" customers use to access the Rocketlane portal without 2FA?
Rocketlane's "magic links" are designed with security in mind, even without traditional 2FA:
- Unique and Time-Sensitive: When a customer logs in, the system generates a unique, single-use, time-sensitive token (valid for 7 days) and sends it to their registered email address.
- Secure Verification: The customer's browser securely transmits this token back to Rocketlane's backend for rigorous verification and validation. Access is granted only if the token is valid and unexpired.
- Encryption: All data transmissions during this process are encrypted to protect sensitive information.
- Non-Reusable: The token cannot be reused or exploited after its initial use or expiration.