Korvex provides enterprise-grade security features to protect your data and accounts.
Two-Factor Authentication (2FA)
Setup
- Go to Profile or Settings > Security
- Click Enable 2FA
- Scan the QR code with your authenticator app (Google Authenticator, Authy, etc.)
- Enter the 6-digit verification code to confirm
Recovery
Keep your backup codes in a secure location. If you lose your authenticator device, use a backup code to regain access.
Passkeys (WebAuthn/FIDO2)
Passkeys provide passwordless login using biometric authentication (fingerprint, face ID) or hardware security keys.
- Go to Profile > Security
- Click Add Passkey
- Follow your browser's prompt to register a passkey
- Name your passkey for identification (e.g., "MacBook Touch ID")
Audit Logs
The audit log records all significant actions:
- Login attempts (successful and failed)
- Role and permission changes
- Client data exports
- Configuration changes
- API key creation and revocation
Best Practices
- Enable 2FA for all team members, especially those with Admin access.
- Use passkeys where possible — they're phishing-resistant and more secure than passwords.
- Review audit logs monthly for unexpected access patterns.
- Rotate API keys annually.