Draft for review. Statuses and facts are being verified before publication.
KuraplanTrust Center
Controls

Access control

Passwordless sign-in with one-time codes

In placeCriticalVerified 15 September 2026ST4S A2 (answered as option C with explanation: no passwords), A11 (not applicable)

What this control means

Kuraplan has no passwords. Teachers sign in with Google or a 6-digit code emailed to them: single use, expires after one hour, rate-limited. Codes are never stored in plain text.

What we found

Sign-in is by Google or a single-use emailed code. Code lifetime reduced from 24 hours to 1 hour; breach-list and length rules apply to the unused password path.

How we verified it

  1. Confirmed from the authentication database that no account uses a password: 17,464 Google identities, 49,366 email-code identities, zero password factors in use.
  2. Reduced the emailed code lifetime from 24 hours to 1 hour and confirmed the setting applied.
  3. Recorded the rate limits that apply to code requests.

Still to do

  • Screenshot the rate-limit settings for the evidence pack.

Evidence (private, draft only): kuraplan-st4s-evidence/02-access/2026-09-15-auth-config-change.txt

Questions about this control: security@kuraplan.com