Skip to main content

SEC-002 โ€” Multi-Factor Authentication

Document: SEC-002Type: StandardStatus: ApprovedOwner: Engineering OperationsVersion: 4.2.0Updated: 2026-07-17

Policyโ€‹

Multi-factor authentication is mandatory for Tier 1 platforms that control identity, source code, domains, production hosting, customer data or billing.

Tier 1 Platformsโ€‹

PlatformPrimary identityRequired controls
Google Workspaceadmin@cloudberrie.comMFA, recovery method, protected admin access
GitHubcb-engopsMFA, recovery codes, organization enforcement before inviting members
Cloudflareaccounts@cloudberrie.comAuthenticator or passkey plus stored recovery codes
Domain registrarBusiness-controlled loginMFA and registry lock where available
Firebase / Google CloudAuthorized company identityMFA and least-privilege access

Preferred Authentication Orderโ€‹

  1. Passkey or hardware security key, when supported.
  2. Authenticator application.
  3. Platform recovery codes stored in Apple Passwords and one controlled offline recovery copy.
  4. SMS only as a fallback when stronger methods are unavailable.

Validationโ€‹

MFA was tested after enrollment Recovery codes were stored before leaving the setup screen The login identity is business-controlled A second recovery method exists where supported