Security & Risk Management

Multi-Factor Authentication & Biometrics

Mandatory, risk-adjusted authentication that protects every customer without adding friction for the ones you already trust.

One policy, two platforms

The same protection, built for how each platform is actually used

Security isn’t a copy-paste between web and mobile, each platform gets the setup that makes sense for it.

app.finhost.io/settings
FinHost web security settings showing two-factor authentication with method dropdown

On the web

  • Two-factor authentication always on, no disable switch
  • Switch between SMS and an authenticator app anytime
  • Set up an authenticator app by scanning a QR code
FinHost mobile app showing biometric login and verification code entry

On mobile

  • Everything available on the web, plus:
  • Set up an authenticator app with one tap, no QR scanning needed
  • Face ID or Touch ID login, offered right after onboarding
  • Push-based confirmation for sensitive actions like payments

How protection adapts to risk

Security that tightens or relaxes based on real risk

The same policy applies to every customer, what changes is how much friction it adds, based on what’s actually known about the account.

STEP 01

Account created

Only authenticator-app MFA is available before verification: SMS isn’t offered yet.

STEP 02

Identity verified

Once KYC or KYB is confirmed, full MFA, including SMS, activates automatically.

STEP 03

Every login

MFA is required every time. There’s no setting to turn it off.

STEP 04

Method managed

Customers switch between SMS and an authenticator app any time from settings.

STEP 05

Recovery available

Lost authenticator access is resolved through a guided reset, with support assistance if needed.

STEP 06

Sensitive actions

Transaction MFA adds a second, push-based confirmation for payments specifically.

Why FinHost

Security that protects the business, not just the checkbox

Security you can’t accidentally turn off

There’s no setting for a customer, or an intruder with a stolen password, to disable authentication. It’s enforced automatically, every time.

Friction where it matters, not everywhere

CAPTCHA and full MFA scale down automatically for verified customers: the people least likely to be a risk in the first place.

One policy, enforced consistently

The same rules apply platform-wide, so security posture doesn’t depend on individual customer choices or configuration drift.

Configuration

Adapt enforcement to your platform

Tenant-level enforcement

MFA is mandatory in production by default, with the option to disable it for a staging or demo environment.

Method availability by status

SMS-based MFA is only available to verified accounts. Unverified accounts are restricted to an authenticator app.

Fraud-prevention layer

CAPTCHA protects sign-up and login from automated abuse, and steps aside automatically for verified customers.

Frequently Asked Questions

Can customers turn off multi-factor authentication?
No. Authentication is enforced automatically on every login, there’s no setting for a customer to disable it.
What security applies before a customer is verified?
Unverified accounts can still enable MFA, but only through an authenticator app. SMS-based MFA is restricted until identity verification is confirmed.
What if a customer loses access to their authenticator app?
Access can be restored through a guided reset, with support assistance if needed, issuing a new authenticator setup.
Is biometric login required, and is it available on the web?
No, it’s optional, and it’s a mobile-only convenience: Face ID or Touch ID isn’t available in the web app.
Why do some customers see a CAPTCHA and others don’t?
CAPTCHA protects against automated abuse during sign-up and SMS-based login. It’s skipped automatically for customers who are already identity-verified.
What is Transaction MFA?
An additional push-based confirmation step for sensitive actions like payments a second checkpoint beyond login, for the moments that matter most.

See Multi-Factor Authentication & Biometrics in action

Explore how FinHost enforces adaptive, risk-based security across every customer account.

Contact Us