Brute-force protections

Strivacity is designed from the ground up to secure against malicious behavior. This security-by-design approach mitigates against brute-force attacks and limits the ability of suspicious entities to gain unauthorized access to your systems.

Password brute-force protection

When repeated failed password attempts are detected from the same IP address for a specific account, Strivacity automatically terminates the session to prevent further login attempts.

MFA brute-force protection

When repeated MFA failures are detected for a specific account (such as incorrect one-time passwords or expired magic links) from the same IP address, Strivacity automatically terminates the session.

Suspicious IP throttling

Strivacity monitors the rate of account-related actions originating from a single IP address, including:

  • Login
  • Registration
  • Self-service password reset
  • Forgotten username
  • MFA requests
  • Admin Console access

If activity exceeds defined thresholds, the session is automatically terminated to mitigate abuse.