Owner MFA
Privileged control sessions require an authenticator code or a one-time recovery code.
SECURITY
Private URLs are not treated as protection. Eonturn uses authentication, MFA, role-based permissions, secure sessions, CSRF controls, rate limits, encrypted secrets, audit chains and customer-safe backups.
Privileged control sessions require an authenticator code or a one-time recovery code.
Support, releases, finance, administration and auditing can be separated instead of sharing one unrestricted login.
Eonturn Control uses shorter absolute and idle session limits than normal customer accounts.
Installers are stored outside the public web root, validated, hashed and published separately from upload.
Schema migrations, atomic database writes and rollback backups reduce the chance of losing customer records during updates.
High-risk actions are recorded in a linked HMAC audit chain that can be verified from Eonturn Control or the command line.