MFA for web & mobile applications #1389
harshit-yc
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
As Yosemite Crew continues to scale across clinics and pet parents — including sensitive medical records, prescriptions, payments, and upcoming AI integrations — account security becomes mission-critical.
Today, authentication is primarily email/password. We should add Multi-Factor Authentication (MFA) across:
This reduces risk of account takeovers and improves trust + enterprise readiness.
Scope: Should MFA be mandatory for clinic staff and optional for pet parents? Or mandatory for both?
Methods: Which MFA methods should we support first?
Risk-based MFA: Should MFA trigger only on:
UX: How do we reduce friction for busy clinic staff while keeping security strong?
Admin protection: Should super-admin roles require stricter MFA (mandatory + no SMS)?
Mobile re-auth: Should mobile apps support biometric unlock (Face ID / Touch ID) layered on top of MFA?
Design
Development
Backend/API
Testing
Pet parents: More confidence their pet’s records are protected.
Clinics: Reduced compromise risk; enterprise-ready security.
Platform: Better posture for compliance efforts (SOC2-like readiness).
Beta Was this translation helpful? Give feedback.
All reactions