Authentication
Local and Google sign-in, MFA / 2FA challenges with recovery codes, workspace-specific OIDC / SSO, time-limited password resets, and progressive temporary lockouts.
This page focuses on the technical controls inside Dashmon: MFA with recovery codes, workspace-specific OIDC / SSO, admin step-up verification, scoped API tokens, audit visibility, and responsible disclosure. For procurement, legal, privacy, and broader customer review, use the Trust Center.
Local and Google sign-in, MFA / 2FA challenges with recovery codes, workspace-specific OIDC / SSO, time-limited password resets, and progressive temporary lockouts.
Sensitive admin views are protected behind admin access checks and additional one-time verification before platform-wide or billing-sensitive workflows are shown.
Labeled API tokens, access scopes, expiry, recent-use visibility, request tracing, account security activity, shared-workspace governance, and blocked-action auditing.
Protected app and API areas, premium feature gating, admin-only routes, owner-only governance boundaries, delegated workspace controls, and additional verification for platform-wide admin workflows.
CSP, HSTS, referrer-policy, nosniff, permissions-policy, and noindex controls for private surfaces help reduce accidental exposure.
Dashmon records sign-in activity, MFA and recovery-code events, token changes, admin verification, billing-sensitive actions, and protected changes for later review.
A public security.txt endpoint is available for responsible disclosure and contact details.
Dashmon supports MFA with recovery codes, workspace-specific OIDC / SSO, SSO enforcement, domain restrictions, required or denied group policy, and role-aware workspace access.
Dashmon exposes practical controls and public trust material, but long-term reliability evidence, broader compliance proof, and external security review or penetration testing should still be part of production go-live planning.
Use this page for authentication, workspace identity, admin protection, API token governance, audit visibility, and disclosure controls. Use the Trust Center when the review also needs privacy, legal, operational-readiness, or procurement material.
Review this page for MFA, workspace OIDC / SSO, audit visibility, admin verification, and responsible disclosure.
Use public privacy and terms pages for data handling, service expectations, billing, and acceptable use questions.
API authentication, request tracing, and shared-workspace behavior are documented publicly, and Help Center points customers to the fastest next step.
Public security page, privacy policy, terms, contact details, help-center guidance, API docs, and a generated security.txt preview.
Detailed audit exports, restore proof, release evidence, dependency review output, and internal compliance artifacts should be shared separately after disclosure review.
For procurement or security-review requests that need a curated bundle, use contact so Dashmon can share the right pack safely.
Security, privacy, legal terms, operational trust and company information remain separate so each topic stays clear and specific.