MFAPortal

Security and architecture

MFA Portal handles authentication events, not application data. This page describes exactly what passes through the service and what does not.

What we store

What we never receive: your users’ password hashes, the contents of your applications, mailbox or file data, and any client agent on user devices. The password check stays with your identity provider; we only decide whether the second step was satisfied.

Regions and hosting

Each tenant is provisioned in one region, chosen at setup: eu-central-1 (Frankfurt) or us-east-1 (Virginia). Tenants are logically separated and data is not replicated across regions. Backups remain in the tenant region.

Encryption

Administrator controls

Assurance

Sub-processors

ProviderPurposeLocation
Amazon Web ServicesHosting, KMS, backupsTenant region (eu-central-1 or us-east-1)
Mailgun TechnologiesEnrolment invitations and account noticesUnited States / European Union
TwilioSMS fallback codes, where a tenant enables itUnited States
DatadogService monitoring and error trackingUnited States

Sub-processors are listed in the privacy policy. Tenants are notified 30 days before a new one is engaged.

Deletion and export

Closing a tenant exports what you ask for (users, enrolment status, audit events as JSON or CSV) and deletes the rest within 30 days, with a written confirmation. Individual users removed from the directory are deleted at the next sync.

Security contact. security@mfaportal.net. Reports from client security teams are answered by the on-call engineer, and confirmed vulnerabilities are disclosed to affected tenants once a fix is available.