NominalQC Feature

Two-Factor & Account Security

Authenticator-app two-factor, the owner’s power to require it by role, and a recovery path that does not depend on a support ticket.

Try this in the live demo — no signup →

Settings → Policies → Two-factor: require two-factor for owners, admins, inspectors or viewers, with a grace period in daysSettings → Security: two-step verification is off, with the button to set it up with an authenticator app

What you can do

  • Two-factor sign-in with any authenticator app, in Settings → Security — once it is on, a password alone no longer opens the account
  • One-time recovery codes issued at enrollment, and regenerated whenever you like without turning two-factor off
  • Owners require two-factor by role — owner, admin, inspector, viewer — with a grace period; members who have not enrolled are emailed the deadline, reminded on every screen, and asked to enroll before anything else opens once it passes
  • Lost phone and codes: an owner resets a teammate’s two-factor from Settings → Team (admins can for inspectors and viewers) — logged, and the person is emailed. The owner’s own is reset only by NominalQC support after identity checks
  • New accounts verify their email address before inviting teammates or exporting data
  • Change your sign-in email yourself: one link to the new inbox, and a notice to the old one
  • Password-reset and invite emails come from nominalqc.com, and their links land on the app’s own domain
  • Every organization’s records are isolated at the database layer, on every table

Questions people ask

Can we require two-factor for everyone?
Yes. The owner picks the roles in Settings → Policies → Two-factor and sets a grace period. Members get the deadline by email; after it, the app asks them to set up two-factor before anything else opens.
What happens if someone loses their phone?
They sign in with a recovery code. If those are gone too, the owner resets their two-factor from Settings → Team, and they set it up again. Every reset is logged and the person is emailed.
Do you support single sign-on (SSO)?
Not today. Sign-in is email and password, with two-factor you can require by role.

See it with your own parts.

Free for one user. No credit card required.

Create your free account