Security and access controls

Customer data, account access and staff access stay separate.

Rival Spy isolates each organization’s data, checks protected actions on the server and gives staff a separate access path.

Account protection

Passwordless email, Google, passkeys, one-time recovery codes, session review and revocation are available through self-serve account controls. Consequential changes require recent authentication.

  • Passkey challenges are short-lived, browser-bound and single-use
  • Verified email change notifies the old address and ends prior sessions
  • OIDC and SAML enforcement retain an audited break-glass owner path

Customer and staff boundaries

Owner, admin, analyst and viewer permissions are enforced on the server. Staff use separate MFA-protected roles and time-limited, case-specific support access with a visible audit record.

Evidence and credentials

Customer secrets are shown once or stored encrypted. Protected records cannot be overwritten, exports exclude credential material and Rival Spy data remains isolated from other Marquorum products.

Production controls

Production monitoring, security events, backup checks and incident runbooks provide operational evidence without presenting internal testing as an external security certification.