CyberSpec

Built with real account security

Security tools that don't practice what they preach are a liability. Every CyberSpec account — including yours — is protected the same way we'd expect any security-conscious team to protect theirs.

Mandatory two-factor authentication

Every account requires TOTP MFA, on every sign-in method — password, Google, or GitHub. No opt-out.

Google & GitHub sign-in

OAuth logins trust the provider's own verified-email claim and go through the same MFA enrollment as email/password accounts.

Backup codes for account recovery

Ten single-use backup codes are generated at MFA enrollment, so losing your authenticator app never locks you out permanently.

Session control

See every active session across your devices and remote-sign-out any of them, right from Settings.

MFA is not a setting you can leave off

Most tools ship two-factor as an option, then report an adoption percentage. CyberSpec enrols TOTP at account creation and enforces it on every sign-in method — email and password, Google, and GitHub alike. There is no organisation-wide toggle to disable it and no per-user exemption, because the account that skips MFA is always the one that matters.

OAuth logins are held to the same bar

Signing in with Google or GitHub trusts the provider's own verified-email claim rather than sending a second verification mail, but it does not skip anything after that: OAuth accounts go through the identical MFA enrolment as email and password accounts. You can also link a second provider to an existing account, so losing access to one identity provider does not lose you the account.

Losing your phone is not losing your account

Ten single-use backup codes are generated at MFA enrolment. If the authenticator app is gone, a backup code gets you in; if the codes are gone too, recovery runs through email verification. Both paths are recorded in the account audit log, so an unexpected recovery is visible after the fact rather than silent.

You can see and end every session

Settings lists every active session across your devices with the ability to sign any of them out remotely. Organisation accounts add role-based access — Owner, Admin, Analyst, Viewer — enforced server-side on every action through a central permission matrix rather than ad-hoc checks scattered across routes, so a Viewer cannot reach an action simply because a page forgot to hide the button.

Enterprise SSO without dropping the floor

Enterprise organisations can point CyberSpec at their own SAML or OIDC identity provider — Okta, Azure AD, and the like. MFA still applies on top unless the customer's own IdP already enforces it organisation-wide. That trade-off is documented rather than silently made, because "we turned MFA off for the SSO tenant" is exactly the sort of thing that should never be a surprise.

Your data stays exportable and deletable

Every account can export its data as JSON and request account deletion from the privacy settings, without opening a support ticket. API keys are scoped to a single organisation and can be revoked instantly. The point of all of it is the same: a security vendor that makes leaving hard has an odd definition of trust.

Reporting a vulnerability in CyberSpec itself? Contact details and our PGP key are published at /.well-known/security.txt per RFC 9116. For how findings map to audit controls, see SOC 2, ISO 27001 and PCI DSS coverage.