> For the complete documentation index, see [llms.txt](https://opora.gitbook.io/opora-health-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://opora.gitbook.io/opora-health-documentation/log-in.md).

# Log-in

The OPORA Platform implements secure login mechanisms across the mobile application and web dashboard, aligned with regulatory standards such as GDPR, HIPAA, and the EU AI Act.

* **Authentication Methods**:\
  Users authenticate using email and password credentials, with passwords stored securely using industry-standard hashing algorithms.
* **Two-Factor Authentication (2FA)**:\
  Role-based 2FA is enforced for all users accessing sensitive data or administrative functions. This adds an additional layer of security by requiring verification via a secondary channel (one-time code via SMS, via the Twilio service).
* **Mobile Application**:\
  Login supports biometric options (Face ID, fingerprint) where available, in addition to standard credential-based access. Sessions are time-limited and encrypted.
* **Web Dashboard**:\
  Secure login is enabled through the user portal. Session expiration policies are configurable to match institutional security requirements.

All login events—including successful and failed attempts—are captured in encrypted audit logs to support forensic analysis and compliance audits. Access is role-scoped by design, minimising exposure to personal or sensitive health data.

<figure><img src="https://1006254083-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlOhtEUn0IGCvXdlPOQkq%2Fuploads%2FgfSK9dAogehsAVCADzaT%2Fimage.png?alt=media&amp;token=14fd3b55-0859-407e-ab0e-d1a191bd35e8" alt=""><figcaption><p>Biometric Authentication</p></figcaption></figure>
