February 27, 2026 · Foundation · Passwordless Authentication

Passwords are gone — magic link + mandatory TOTP is the only way in

Credential stuffing is the top attack vector against SaaS. Removing passwords eliminates the class. Magic link + mandatory TOTP is the primary flow, with passkeys and social login as alternatives. The external portals (DD room, investor portal, vendor portal) use the same passwordless model — no easier back door.

What changed

Passwordless authentication is now the only way to sign in to vCISO Lite. Passwords are gone — not deprecated, not opt-out, gone. The primary login flow is magic link plus mandatory TOTP, with passkeys and social login (Google, GitHub, Microsoft) as alternatives.

Primary flow
Magic link plus mandatory TOTP at every sign-in. Links are single-use and expire in 10 minutes. NIST SP 800-63B recognizes this pattern as multi-factor authentication with high assurance.
Passkeys
WebAuthn-standard, syncable across a customer's device fleet, phishing-resistant by construction. The low-friction option for customers whose devices support them.
Social login
Google, GitHub, and Microsoft for customers who would rather delegate identity to a provider they already trust. The same TOTP gate applies where the provider does not already enforce a second factor.
External portals
The DD room portal for target companies, the investor portal for LP-facing deliverables, and the vendor portal for questionnaire completion all use the same passwordless model. No easier door for a less-authenticated external user.
Migration
Existing password logins convert on next sign-in: enter your email, click the magic link, set up TOTP, done. The old password is invalidated the moment the new factor is set.

Why it matters

Credential stuffing is the top attack vector against SaaS applications, and the platform we’re building holds a customer’s compliance posture, vendor risk register, policy library, and audit-relevant evidence. A stolen password on this platform is a bigger deal than a stolen password on most SaaS products. Removing passwords eliminates the entire attack class.

There’s also an operational argument: with no passwords, there are no password-reset flows to maintain, no forgot-my-password support tickets to triage, no bcrypt hashing infrastructure to audit, no password-complexity rules to argue about, and no leaked-password checks to run against Have I Been Pwned. It’s less code, less surface area, less to break.

Availability

Live today for every customer on every tier, including the external DD room, investor, and vendor portals.

Customers with existing password logins migrate transparently on next sign-in: enter your email, click the magic link, set up TOTP, done. The old password is invalidated the moment the new factor is set, so there is no window where both routes are open.

Known limitations

Magic links are email-bound, which makes the mailbox a load-bearing part of the sign-in flow. The TOTP second factor is what keeps a compromised mailbox from being enough on its own.

Passkey availability depends on the customer's device and browser. On platforms without WebAuthn support, magic link plus TOTP or a social provider remains the path.

A lost TOTP device requires the account-recovery flow with identity re-verification. There is no password-reset shortcut back in because there is no password.