Platform · Security & Access

Enterprise-grade account security, on by default

Two-factor authentication, step-up re-auth for sensitive actions, role-based access with two permission planes, and an immutable audit trail — built in from the start, without getting in your way.

Available on: All plans

Security is usually an afterthought bolted on later — which is exactly when it fails.

What changes for your business

  • Protect your account with real 2FA — no SMS, no gimmicks.
  • Limit what each team member can do with genuine role-based access.
  • Prove who did what, when, with an immutable audit trail.
  • Get strong security that stays out of the way of everyday work.

Key capabilities

Two-factor authentication

App-based TOTP 2FA with one-time recovery codes — stronger than SMS and not tied to your phone number.

Step-up ('sudo mode')

High-risk actions require a fresh second factor or password re-entry, so a stolen session alone can't do damage.

Role-based access (RBAC)

Two independent permission planes — website workspace and hosting/infrastructure — with scoped roles and plain-English permission summaries, actually enforced.

Sessions & sign-in history

See every signed-in device, revoke any of them, review sign-in history, and get security emails for password, 2FA and new-device events.

Immutable audit trail

Every security-relevant action is recorded in a categorised, filterable, exportable log that can't be edited after the fact.

How businesses use it

A business protecting customer data

Turn on 2FA, give staff only the access they need, and rely on step-up to guard destructive actions.

An agency with several team members

Assign scoped roles across the website and infrastructure planes so everyone has exactly the access their job needs.

Works with

  • TOTP authenticator apps
  • Cloudflare Turnstile (bot protection)
  • Optional PostgreSQL row-level security

Built to be trusted

Security is on by default, not an upsell. Passwords use scrypt, secrets are encrypted with AES-256-GCM, sessions are stored only as hashes, and every tenant's data is isolated and negative-tested. The full posture is documented in our security pages.

Questions, answered

The core protections — encrypted secrets, hashed sessions, tenant isolation, audit logging — are on by default. Two-factor authentication is one click to enable and strongly recommended.

Works well with

See it working on your own business

Start with a free Origin Session — about 15 minutes — and watch LimeOrigin build around your business.

Security & Access — 2FA, step-up, RBAC and audit, by default · LimeOrigin