๐Ÿ”’

E1 Unico Corporation

Multi-Factor Authentication (MFA) Policy
Effective Date: June 2026  |  Version: 1.0  |  Classification: Internal / Regulatory
Policy Owner: Manuel Montemayor Jr., Founder & CEO
Contact: Unico@E1Unico.com  |  1 (833) 318-6426  |  e1unico.com
BBB Accredited Business

Policy Statement: E1 Unico Corporation mandates phishing-resistant Multi-Factor Authentication (MFA) for all access to systems that store, process, or transmit consumer financial data. MFA is enforced at the infrastructure, application, and administrative levels โ€” no single-factor access is permitted for any critical system. This policy applies to all human administrators, developers, and authorized personnel without exception.

1. MFA Requirement Scope

Phishing-resistant MFA is required for all access to the following critical systems:

SystemRoleMFA MethodStatus
Vercel Production application hosting & environment secrets Authenticator app (TOTP) + Passkey / Biometric โœ… Active
Neon (PostgreSQL) Production database storing all financial data & PII Authenticator app (TOTP) + Passkey / Biometric โœ… Active
GitHub Source code repository โ€” enforced org-wide Authenticator app (TOTP) + Passkey / Biometric โœ… Active
Plaid Dashboard API key management & financial data access controls Authenticator app (TOTP) โœ… Active
Stripe Dashboard Payment processing & financial transaction management Authenticator app (TOTP) + SMS backup โœ… Active
UnicoOS Admin Multi-tenant SaaS platform โ€” admin accounts Password + device-bound session โœ… Active

2. MFA Standards โ€” Phishing Resistance

E1 Unico Corporation enforces phishing-resistant MFA methods that cannot be intercepted or replayed by a phishing attack:

Explicitly prohibited: SMS-only MFA is not accepted as a sole second factor for critical system access due to SIM-swap vulnerability. SMS is only permitted as a backup recovery method.

3. Enforcement

4. MFA for Non-Human Systems

Automated and service accounts do not use MFA โ€” instead they use phishing-resistant equivalent controls:

5. MFA Implementation Evidence

The following screenshots document active MFA enrollment across critical systems as of June 2026:

5.1 Vercel โ€” MFA Active

[ Screenshot: Vercel Account Settings โ†’ Security โ†’ Two-Factor Authentication: Enabled ]

5.2 GitHub โ€” MFA Active (Organization-wide enforcement)

[ Screenshot: GitHub Settings โ†’ Password and Authentication โ†’ Two-Factor Authentication: Enabled ]

5.3 Neon โ€” MFA Active

[ Screenshot: Neon Dashboard โ†’ Profile โ†’ Security โ†’ Two-Factor Authentication: Enabled ]

5.4 Plaid Dashboard โ€” MFA Active

[ Screenshot: Plaid Dashboard โ†’ Account Settings โ†’ Security โ†’ MFA: Enabled ]

Policy Approval

This MFA Policy has been reviewed, approved, and is actively enforced across all E1 Unico Corporation critical systems as of the effective date below.

Manuel Montemayor Jr., Founder & CEO
E1 Unico Corporation

Annual โ€” June 2027