← Changelog
SecurityMay 14, 2026
MFA step-up authentication for gate approvals
Approving a gate submission or publishing a live policy bundle now requires a valid MFA step-up token when the user has enrolled. TOTP secrets are AES-256-GCM encrypted. Backup recovery codes generated at enrollment. MFA setup page at /settings/security. Bulk approve also enforces step-up — closes the privilege escalation gap on batch operations.