Access & Security
Multi-Factor Authentication Policy
How Before the Call supports additional identity verification — a second layer beyond the password to help protect Customer accounts and administrative information.
- Document ID
- SEC-003
- Version
- 1.0.0
- Status
- Active
- Classification
- Public
- Owner
- Big Bull Technologies, LLC
- Effective
- 20 July 2026
- Next review
- July 2027
01 Purpose
Big Bull Technologies, LLC (“Big Bull Technologies,” “BBT,” “we,” “our,” or “us”) recognizes that passwords alone may not always provide sufficient protection against unauthorized account access.
This Multi-Factor Authentication (“MFA”) Policy explains how Before the Call (“B4C”) supports additional identity verification methods to help protect Customer accounts and administrative information.
02 Our Philosophy
Authentication should balance security with usability.
Multi-Factor Authentication adds an additional layer of protection by requiring more than one method of identity verification before granting access to an account.
As Before the Call evolves, MFA capabilities may expand to support additional authentication technologies and enterprise security requirements.
03 What Is Multi-Factor Authentication?
Multi-Factor Authentication requires two or more independent factors to verify a user’s identity. These factors generally fall into three categories:
- Something you know (such as a password or passphrase)
- Something you have (such as a trusted device or authentication application)
- Something you are (such as biometric authentication provided by the device)
Using multiple factors helps reduce the risk of unauthorized account access if one factor becomes compromised.
04 Supported Authentication Methods
Before the Call currently supports one or more of the following authentication methods, depending on platform, subscription level, and Department configuration:
- Passkeys (WebAuthn)
- Email and password
- Magic links
- Email verification codes
- One-time passcodes (OTP)
- Authenticator applications (where available)
- Device-based authentication
- Biometric authentication through supported operating systems
- Enterprise identity providers (where available)
Availability may vary as the platform evolves.
05 Department Controls
Departments may configure authentication requirements based on organizational needs. Examples may include:
- Optional MFA for Members
- Required MFA for Department Administrators
- Required MFA for users with elevated permissions
- Department-wide MFA enforcement
- Future enterprise authentication policies
Available configuration options may vary by subscription plan.
06 Enrollment
When MFA is available, Authorized Users may be guided through an enrollment process that includes:
- Selecting an authentication method
- Verifying the selected method
- Confirming successful enrollment
- Establishing recovery options where supported
Departments may require enrollment before granting access to certain administrative functions.
07 Recovery
If an Authorized User loses access to a registered authentication method, account recovery may require additional identity verification.
Recovery procedures are intended to protect Customer information while allowing legitimate users to regain account access.
Big Bull Technologies may decline recovery requests that cannot be reasonably verified.
08 Lost or Replaced Devices
Users who replace or lose a trusted device should update their authentication settings as soon as reasonably practical.
Departments may require re-verification before restoring administrative access.
Prompt reporting of lost devices helps reduce the risk of unauthorized access.
09 Biometric Authentication
Where supported by the operating system, users may choose to unlock the B4C application using biometric authentication. Examples include:
- Face ID
- Touch ID
- Fingerprint authentication
- Other supported biometric technologies
Biometric data is processed by the operating system and hardware provider. Big Bull Technologies does not receive, store, or process biometric templates.
10 Security Benefits
Multi-Factor Authentication helps protect against:
- Stolen passwords
- Credential reuse
- Phishing attacks
- Unauthorized account access
- Certain automated attacks
- Credential stuffing
While MFA significantly improves account security, no authentication method can eliminate all security risks. Users should continue following good security practices.
11 Future Authentication Technologies
Big Bull Technologies continually evaluates emerging authentication technologies. Future enhancements may include:
- Expanded passkey capabilities
- Enterprise Single Sign-On (SSO)
- Microsoft Entra ID
- Google Workspace
- Okta
- SAML
- SCIM provisioning
- Hardware security keys
- Additional enterprise authentication providers
Future capabilities will be introduced as appropriate to customer needs and platform development.
12 Continuous Improvement
Authentication practices are reviewed periodically to align with:
- Industry standards
- Security best practices
- Customer requirements
- Regulatory expectations
- Platform capabilities
Big Bull Technologies may introduce additional authentication controls as threats and technologies evolve.
13 Changes to This Policy
Big Bull Technologies may update this Multi-Factor Authentication Policy periodically.
Material changes will become effective on the published Effective Date after reasonable notice has been provided through the Services, our website, email, or another appropriate communication method.
14 Contact
Questions regarding Multi-Factor Authentication may be directed to Big Bull Technologies.
Big Bull Technologies, LLC
Email: ashlea@bigbulltech.io
15 Related Documents
16 Revision History
| Version | Date | Description |
|---|---|---|
| 1.0.0 | July 2026 | Initial publication. |