RemakeCV

Two-factor authentication

Add a second authentication factor to RemakeCV logins. The highest-value security setting on an account holding candidate personal data.

Two-factor authentication requires a time-based code from an authenticator app in addition to your password. Because RemakeCV accounts hold candidate personal data, enabling it is the single highest-value security change you can make. It is configured per user in account settings.

Why does it matter here specifically?

A RemakeCV login can reach every CV your agency has processed. A compromised password without a second factor is therefore a personal-data breach affecting candidates who never had a relationship with the attacker — and a reportable one.

Recruitment credentials are also actively targeted, because candidate databases have resale value. This is not a theoretical risk.

How do I set it up?

  1. Open your account settings

    Find the two-factor authentication section.

  2. Scan the QR code

    Use any authenticator app — Google Authenticator, Microsoft Authenticator, Authy, 1Password, or your password manager's built-in support.

  3. Enter the six-digit code

    This confirms the app and RemakeCV are in sync.

  4. Save your eight backup codes

    You are shown eight codes, each usable once. Store them somewhere that is not the phone running the authenticator — a password manager or a physical safe. This is the step people skip and later regret.

Warning:

Backup codes stored only on the device running your authenticator app are useless — losing the phone loses both. Keep them somewhere separate.

They are single-use, so cross them off as you spend them. They also work in place of an authenticator code when disabling two-factor authentication.

Who should turn it on?

SituationRecommendation
Any account holding candidate CVsEnable it
Clients audit your securityEnable and enforce company-wide
Regulated sector recruitmentEnforce, and pair with prompt offboarding
Consultants sharing a deviceEnforce

What if I lose access?

Use a recovery code. If you have none, contact support@remakecv.com. We will need to verify your identity before resetting the factor, which necessarily takes longer than using a code you saved.

Can we require it for everyone?

Not with a switch — there is no company-wide enforcement setting. Two-factor authentication is enabled by each user on their own account, because setup needs their own device.

In practice that makes it a rollout task rather than a configuration one:

  1. Make it part of onboarding

    Set it up on day one, before the account is used in anger.

  2. Ask existing users to enable it, with a date

    An open-ended request gets ignored.

  3. Check coverage

    Ask us at support@remakecv.com if you need to confirm who has it enabled.

This matters most if your clients audit your security or you recruit in a regulated sector — the accounts most likely to be compromised are exactly the ones that would opt out.

Two-factor authentication is one part of a wider picture — see security, DPAs and sub-processors.

What about single sign-on?

SAML single sign-on is supported and in use by enterprise customers. Users signing in through your identity provider are provisioned automatically on first login, and your provider's own MFA policy applies.

Setup is handled by RemakeCV — email support@remakecv.com with your identity provider and the email domains it covers.

Frequently asked questions

Which authenticator apps work?
Any app supporting time-based one-time passwords — Google Authenticator, Microsoft Authenticator, Authy, 1Password and most password managers.
What if I lose my phone?
Use one of your eight backup codes. Without them, recovery requires contacting support@remakecv.com to verify your identity, which takes longer.
Can 2FA be required for everyone?
Not through a setting — each user enables it on their own device, so company-wide adoption is a rollout task. If you need SSO instead, with MFA enforced by your identity provider, we support that.
Do you support single sign-on?
Yes. SAML SSO is available for enterprise accounts, with automatic user provisioning on first login. Email support@remakecv.com with your identity provider and email domains.

Related articles

Was this page helpful?

Last updated . Still stuck? Email support@remakecv.com or book a call.