Skip to main content

Cloudflare Account Security Baseline

Document: INF-202Type: Standard / SOPStatus: ApprovedOwner: Cloud EngineeringVersion: 4.2.0Updated: 2026-07-17

Required controlsโ€‹

ControlCloudberrie standard
PasswordUnique, generated, stored only in the approved password manager
MFAAuthenticator app required
Passkey / security keyRecommended secondary factor
Recovery codesDownload and store outside the primary device
Recovery inboxaccounts@cloudberrie.com must remain operational
Additional administratorsInvite individual identities later; do not share the owner password

Setup procedureโ€‹

  1. Open profile or authentication settings.
  2. Register an authenticator application and verify one code.
  3. Download recovery codes and record their storage location in the private asset register.
  4. Add a passkey or hardware security key where available.
  5. Log out and confirm login works with the password plus MFA.

Validationโ€‹

MFA challenge appears during a new-session login. Recovery codes are stored and not committed to Git. Browser password reuse is avoided. No personal Gmail account owns the platform.