Two-factor sign-in with any authenticator app, in Settings → Security — once it is on, a password alone no longer opens the account
One-time recovery codes issued at enrollment, and regenerated whenever you like without turning two-factor off
Owners require two-factor by role — owner, admin, inspector, viewer — with a grace period; members who have not enrolled are emailed the deadline, reminded on every screen, and asked to enroll before anything else opens once it passes
Lost phone and codes: an owner resets a teammate’s two-factor from Settings → Team (admins can for inspectors and viewers) — logged, and the person is emailed. The owner’s own is reset only by NominalQC support after identity checks
New accounts verify their email address before inviting teammates or exporting data
Change your sign-in email yourself: one link to the new inbox, and a notice to the old one
Password-reset and invite emails come from nominalqc.com, and their links land on the app’s own domain
Every organization’s records are isolated at the database layer, on every table
Yes. The owner picks the roles in Settings → Policies → Two-factor and sets a grace period. Members get the deadline by email; after it, the app asks them to set up two-factor before anything else opens.
What happens if someone loses their phone?
They sign in with a recovery code. If those are gone too, the owner resets their two-factor from Settings → Team, and they set it up again. Every reset is logged and the person is emailed.
Do you support single sign-on (SSO)?
Not today. Sign-in is email and password, with two-factor you can require by role.