← HELP·SECURITY

Do you support two-factor authentication?

Magic links are already passwordless + per-request, which is effectively phishing-resistant. SMS 2FA is on the roadmap.

Updated May 12, 2026

Our magic-link sign-in already eliminates the biggest attack vector — password reuse — because there are no passwords. Each sign-in requires a fresh email-delivered link with a 60-minute expiry.

That said, traditional 2FA (SMS or authenticator app) is on the roadmap for late 2026 for users who want belt-and-suspenders security. If you want early access to test it, email submissions@bridgecapital.io.

Was this helpful?

Related articles.

Why is there no password? How does magic-link sign-in work?
Bridge uses passwordless auth — we email you a one-tap link instead. Safer + simpler than password reset hell.
How is my data protected?
TLS 1.3 in transit + AES-256 at rest + Supabase row-level security. We never sell your data. Period.
STILL STUCK?

Open a ticket and a human responds within 4 business hours.

Open a ticket →