Skip to content
  • There are no suggestions because the search field is empty.

Lentune Sign-In Security

This article is for IT and security teams, and sets out how Lentune sign-in works so you can assess it, configure your environment for it, and answer questions from your own stakeholders.

Overview

Lentune has moved from passwords to passwordless sign-in. Users enter their email address, receive a six-digit one-time code by email, and enter that code to sign in. Authentication is operated by WorkOS AuthKit, a specialist identity platform. For your team this has two practical consequences: the security of a user’s mailbox now governs their access to Lentune, and your email filtering must reliably deliver our sign-in messages. Nothing changes inside Lentune itself — security groups, security roles, access personas and approval limits all continue to work exactly as before. This article covers what to configure, what to check, and where to escalate.

How Sign-In Works

The sign-in sequence is as follows. A user visits your Lentune web address and is taken to a Lentune-branded sign-in page hosted at login.lentune.com. They enter their email address, which must match the address recorded against their Lentune user record. A six-digit one-time code is emailed to that address. On entering the code they are returned to your Lentune site and signed in.

There is no password at any stage, and no password is stored for the user. Consequently the Reset password control no longer appears on user records in Lentune, and there is no password policy to configure, audit or rotate.

Sessions are scoped to your own Lentune site. A session established on your site does not grant access to any other organisation’s Lentune site, and vice versa. If your staff legitimately access more than one Lentune site, they sign in to each separately.

Secure the Mailbox First

This is the most important section of this article. Because a one-time code is emailed, the ability to read a user’s mailbox is the ability to sign in to Lentune as that user. Your Lentune access is now, in practical terms, as strong as your email access. Mailbox security is therefore the control that matters most, and it sits with you rather than with us.

We recommend the following, in priority order.

  • Enforce multi-factor authentication on your email platform for every user who has a Lentune account. This is the single most effective step you can take, and it means the authentication chain into Lentune includes a second factor that you control.
  • Do not use shared mailboxes for Lentune users. Anyone able to open a shared mailbox can request and read a code, and therefore sign in as that user. Each Lentune user needs an individual mailbox.
  • Review delegate and full-access mailbox permissions for users with high approval limits in Lentune. Delegated access to a mailbox is now effectively delegated access to that person’s Lentune account, including their approval authority.
  • Audit auto-forwarding and inbox rules that copy mail to external or personal addresses, as these can route sign-in codes outside your control.
  • Include one-time codes in your phishing awareness training. Staff should know that a genuine code only ever arrives immediately after they have tried to sign in, and that nobody from Lentune will ever ask them to read a code out.

Session Behaviour and Device Scope

Once a user has signed in, the session persists for well over 24 hours, and that period renews each time they use Lentune. Regular users will therefore be prompted for a code infrequently.

Sessions are per device and per browser. A user with a laptop and a phone signs in on each separately, and each device maintains its own session independently. A new code is required on a new device or browser, in a private or incognito window, or after browser cookies are cleared.

Session lifetime and idle timeout are set by Lentune and are not currently configurable per customer.

Offboard Users Correctly

This is a change in behaviour worth noting. Disabling somebody’s mailbox stops them receiving new sign-in codes, but it does not end a session they already hold. Because sessions persist for an extended period and renew with use, a departing employee with an active session on a personal device could retain access after their mailbox is closed.

When a user leaves, deactivate their Lentune user record as part of your offboarding process. Do not rely on closing the mailbox alone. If you need access revoked immediately and cannot deactivate the user yourself, contact support@lentune.com and we will action it.

Access Control Inside Lentune

This change affects authentication only, not authorisation. Everything that governs what a user can see and do in Lentune is unchanged, including security groups, security roles, access personas, company, branch, department and project scoping, and approval and purchase order value limits.

If you are reviewing your access model at the same time as this change, see Access Personas and how they work and Add a new Lentune User.

Platform Security and Data Handling

Lentune is ISO 27001 certified. Our infrastructure runs entirely on Microsoft Azure, whose data centres hold the same certification, and customer databases are hosted in Azure in Australia. Data is encrypted in transit using HTTPS and TLS, and encrypted at rest in Azure Blob storage by default. Infrastructure is geo-redundant across multiple data centres, and our APIs and web application are protected against denial-of-service attacks.

Database backups provide point-in-time recovery across the last seven days, with weekly backups retained for eight weeks, monthly for 52 weeks and yearly for ten years. Files are retained for 30 days after deletion.

Our full published security position is available at lentune.com/about/security.

Authentication is operated by WorkOS as a sub-processor. The statements above describe the Lentune platform. WorkOS is a separate provider handling the sign-in step, and your security team may wish to assess it separately.

If your organisation has data residency or sub-processor approval obligations, please raise this with us before your switch-over date and we will provide written detail.

API and Integration Access

If your organisation connects to Lentune programmatically — for example through Wholesaler Connect, Construction Finance APIs, or an integration built by your own team or a third party — that access is authenticated separately from user sign-in and is also moving to WorkOS.

API credentials and redirect URLs will need to be reissued or reconfigured. Please contact us well before your switch-over date so we can coordinate this with whoever maintains the integration, and so it does not interrupt any scheduled jobs or overnight processing.

FAQ

Q: Is an emailed one-time code multi-factor authentication?

A: Not by itself. It is passwordless single-factor authentication, where the factor is demonstrated control of the mailbox. This is why we recommend enforcing multi-factor authentication on your own email platform: doing so means the authentication chain into Lentune includes a second factor under your control. [TO BE CONFIRMED BY LENTUNE — whether additional factors within WorkOS, such as an authenticator app, can be enabled per customer]

Q: Can we shorten the session lifetime for our organisation?

A: No, this is set by Lentune and cannot be individually configured.

Q: Does IP-based restriction still apply?

A: Lentune has supported branch-level IP restriction on user records.

Q: How long is a one-time code valid?

A: Codes are valid for a short period and can be used once.

Q: How do we revoke a user’s access immediately?

A: Deactivate their Lentune user record. Closing their mailbox prevents new codes but does not terminate an existing session. If you need immediate revocation and cannot action it yourself, contact support@lentune.com .

Q: What happens if the sign-in service is unavailable?

A: Lentune maintains an alternative sign-in path that our support team can enable if the primary service is unreachable. If you are unable to sign in and suspect an outage, contact support@lentune.com or call us.

Q: Does this change what our users can access in Lentune?

A: No. Authorisation is unaffected. Security groups, security roles, access personas and approval limits all behave exactly as they did before.

Q: A user received a code they did not request. What should we do?

A: Treat it as a possible attempt to use their email address. The code is unusable unless entered, so no action is needed on the account itself, but please report it to support@lentune.com so we can review the activity, and check that the mailbox itself has not been compromised.

Q: Who do we contact with further security questions?

A: Email support@lentune.com and ask for your query to be directed to our information security team. For formal security questionnaires or vendor assessments, please tell us your deadline so we can respond in time.

Need more help? We’re here! We hope our article was helpful. If you need more info or want to connect, drop us an email at support@lent