All features

Two-factor authentication

A TOTP code from an authenticator app on top of the password. One switch makes 2FA mandatory across the company, with a 7-day grace period for everyone to enrol.

An employee portal is a complete export of your company: names, photos, reporting lines, birthdays, phone numbers, grade levels, review results. The password protecting it was invented in five seconds during signup and has almost certainly been reused somewhere else. One breach on an unrelated website, and a stranger has the lot.

Two-factor authentication closes exactly that path: a stolen password stops being enough on its own.

What enrolment looks like

An employee opens Settings → Security and clicks enable. What follows is a two-step wizard.

Step one shows a QR code and a hint about which app to install — Google Authenticator, 1Password, Microsoft Authenticator or Authy on dtpulse.com, Yandex Key or 2FAS on dtpulse.ru. Anything that implements RFC 6238 works: we use the conservative parameters — SHA-1, six digits, a thirty-second window — that every authenticator and corporate password manager understands. If the camera won't cooperate, the key can be typed in by hand.

Step two asks for a current six-digit code. Nothing is stored until that succeeds: during the wizard the secret lives in a signed token that expires in ten minutes, and it is only written to the database — encrypted — once a valid code comes back. An abandoned setup leaves nothing half-finished behind it, which is the usual reason people end up locked out of 2FA systems.

After that, every password sign-in gets a second screen with a six-digit field. The same code can't be replayed, even inside its validity window. Ten consecutive failures lock the account out; the lock clears itself after an idle hour, or immediately if an admin resets it.

Employees can turn 2FA off themselves, but only by supplying the current password and a valid code in the same action. A failure returns one generic message and never hints at which of the two was wrong.

Making it mandatory

In company settings an admin picks the policy: optional, or required for everyone.

Switching to required doesn't throw anybody out mid-session. Each person gets seven days to enrol, and for that whole window the portal shows a banner with a countdown and a button straight into the wizard. New hires get the same seven days from the moment their account is created.

When the grace period runs out, the portal stops letting that person go anywhere except the 2FA setup page. It isn't a lockout or a forced sign-out — it's simply that the only road out leads through a wizard that takes a minute.

So admins can see where the company actually stands, the people list carries a 2FA column right next to Role. No chasing anyone in chat: it's visible who has enrolled and who hasn't.

Losing the phone

There are no recovery codes in DTPulse, and that's a deliberate decision. In a company there is an admin, and an admin is a far more reliable recovery channel than a sheet of codes printed a year ago and lost in the same bag as the phone.

Three routes exist. The first is SSO: if your company signs in through Google, Slack or SAML, the identity provider supplies the second factor and our code screen never appears. The second is an admin opening the employee's record and clicking Reset 2FA — the person signs in with their password and enrols again, and the audit log records who did the reset. Admins can't reset their own, which removes an obvious escalation path for a hijacked session.

The third route covers the case where a company has one admin and it's the admin who lost the phone. Platform support performs the reset, again with an audit entry.

What the audit log records

Every event around the second factor is written down: enabled, disabled, verified, failed verification, admin reset, and company policy changed. That's the exact set of events security questionnaires ask about during procurement, and the same set you need six months later when someone has to reconstruct who removed whose access and when.

Whose time this saves

Admins flip one switch instead of running an internal campaign. The deadline, the countdown and the reminders are the portal's job.

Employees spend a minute on setup and six digits at sign-in. Nothing to store, nothing to lose.

Security teams get a straight answer for the vendor questionnaire: TOTP per RFC 6238, encrypted secrets, company-level policy, full audit trail, admin-controlled recovery.

IT support stops being the recovery channel of last resort for people who lost a code sheet — reset is two clicks on the employee's record.

Getting started

Enable it on your own account first; that's a minute. Check the 2FA column in the people list to see how many have already done it unprompted. When you're ready, switch the company policy to required — everyone gets a week, and the portal does the reminding.

Two-factor authentication is available on every plan, including the free tier for up to 10 people.

Bring your whole HR stack into one portal

Start free

Free for up to 10 people. No card required.