Two-Factor Authentication

One password isn't safety. Two is.

TACHY ships built-in 2FA for every sensitive role — admin, accountant, principal, superadmin. Stolen passwords stop being a school-wide disaster.

Why it matters

The most common school data breach starts with one shared password

Front desk staff share the accountant login. The principal's password is "school@123". A WhatsApp leak of one credential and suddenly anyone with the link can edit fees, marks or transfer students.

TACHY's 2FA requires a second step — a 6-digit code from the authenticator app or an SMS OTP — before sensitive actions go through. Even a leaked password becomes useless.

2FA capabilities

  • ✓ TOTP authenticator (Google / Microsoft / Authy)
  • ✓ SMS OTP fallback for staff without smartphones
  • ✓ Email OTP option
  • ✓ Role-based enforcement (admin → mandatory)
  • ✓ Trusted device skip (30 days)
  • ✓ Login-from-new-location alerts
  • ✓ Backup codes for lost devices
  • ✓ Audit log of every 2FA event
  • ✓ Admin can force 2FA reset
  • ✓ Session timeout for inactive users
India compliance

Built for DPDP Act 2023

India's Digital Personal Data Protection Act expects schools to protect student data with reasonable security. 2FA is one of the simplest, strongest controls — and TACHY ships it as standard.

🔐

Enforce by role

Make 2FA mandatory for accountants and admins; optional for teachers; off for parents.

📍

Geo-fence sensitive ops

Block fee edits or report card publication from outside India / outside school IP.

📜

Audit-ready logs

Every login, 2FA challenge and sensitive action is logged with IP, device and timestamp.

Lock your school data the right way

Demo includes a live 2FA setup walkthrough.

Book a demo