What changed
Passwordless authentication is now the only way to sign in to vCISO Lite. Passwords are gone — not deprecated, not opt-out, gone. The primary login flow is magic link plus mandatory TOTP, with passkeys and social login (Google, GitHub, Microsoft) as alternatives.
Why it matters
Credential stuffing is the top attack vector against SaaS applications, and the platform we’re building holds a customer’s compliance posture, vendor risk register, policy library, and audit-relevant evidence. A stolen password on this platform is a bigger deal than a stolen password on most SaaS products. Removing passwords eliminates the entire attack class.
There’s also an operational argument: with no passwords, there are no password-reset flows to maintain, no forgot-my-password support tickets to triage, no bcrypt hashing infrastructure to audit, no password-complexity rules to argue about, and no leaked-password checks to run against Have I Been Pwned. It’s less code, less surface area, less to break.
Availability
Live today for every customer on every tier, including the external DD room, investor, and vendor portals.
Customers with existing password logins migrate transparently on next sign-in: enter your email, click the magic link, set up TOTP, done. The old password is invalidated the moment the new factor is set, so there is no window where both routes are open.
Known limitations
Magic links are email-bound, which makes the mailbox a load-bearing part of the sign-in flow. The TOTP second factor is what keeps a compromised mailbox from being enough on its own.
Passkey availability depends on the customer's device and browser. On platforms without WebAuthn support, magic link plus TOTP or a social provider remains the path.
A lost TOTP device requires the account-recovery flow with identity re-verification. There is no password-reset shortcut back in because there is no password.