
The typical implementation process for mPass software follows a structured sequence to ensure smooth onboarding. Here's a breakdown of the process:
Initial Consultation and Requirements Gathering: Cerebra conducts a detailed consultation with the client to understand their authentication and security requirements.
The client’s infrastructure is assessed to identify the best way to integrate mPass for managing digital identities and authentication needs.
Platform Customization: The software is tailored to meet specific organizational needs, including integrating it with existing systems like Active Directory, LDAP, or custom databases.
Custom policies, authentication flows, and user access settings are configured.
Installation and Integration: mPass is deployed either on-premise or via the cloud, depending on the client’s preferences and infrastructure.
Integration with existing applications, services, and security systems is performed during this stage.
Testing and Quality Assurance: After deployment, extensive testing is conducted to ensure the authentication processes and integrations work as intended.
This includes security testing, performance evaluation, and troubleshooting any potential issues.
Training and User Onboarding: Training sessions are provided to administrators and end-users to familiarize them with the software.
Documentation, tutorials, and dedicated support are part of the onboarding process to ensure a smooth transition.
Go-Live and Post-Implementation Support: Once the system is fully configured and tested, it goes live.
Continuous support is provided to handle any potential issues, ensure security, and optimize performance.
Timeframe: The process generally takes 4 to 8 weeks, depending on the level of customization, system complexity, and integration requirements. Cloud-based deployments may be quicker, while on-premise setups can take longer due to infrastructure and security considerations.
This phased implementation approach ensures that mPass is fully aligned with the client's security needs while maintaining operational efficiency.
mPass customization process:
Flexible User Registration: mPass provides multiple options for user registration, allowing administrators to choose the method that best suits their organization's needs. This includes manual addition of users and automatic registration through successful authentication with username and password.
Wide Integration Options: mPass can be integrated with numerous enterprise applications using its set of APIs, Agents, and Services. This flexibility allows organizations to customize the integration process based on their existing IT infrastructure.
Customizable Authentication Policies: Organizations can create tailored authentication policies to manage user authentication effectively. These policies can be based on various criteria parameters and applied across multiple integration channels.
Multiple Verification Channels: mPass enables customization of the additional verification factor delivery, offering options such as SMS, Mobile App Push Notifications, Soft Tokens on iOS & Android, and Email.
Scalable Deployment: The system can be customized for enterprise-grade deployment, with multiple authentication servers deployed in redundant mode for high availability.
Active Directory Integration: mPass can be seamlessly integrated with single or multiple Active Directories, allowing for customized selection of specific users or groups for two-factor authentication.
Customizable Reporting: The solution offers various types of reports and dashboards that can be tailored for effective troubleshooting and monitoring specific to an organization's needs.
Risk Mitigation Options: mPass allows for customization of risk management strategies, including the use of temporary or emergency authenticators to deactivate MFA functionality in specific systems or applications.
Tiered Package Options: mPass offers different license packages (Basic, Advanced, Premium) that can be selected based on the organization's specific requirements and number of users.
Customizable Support Levels: Organizations can choose from three support levels (Silver, Golden, Platinum) based on their specific needs, ranging from basic remote support to comprehensive on-site assistance.
mPass (by Cerebra) offers a range of training and support options to ensure that new users can effectively implement and use the multi-factor authentication solution. Here are the key types of training and support:
Guided Setup: New users receive step-by-step guidance during the setup and integration phase, ensuring a smooth implementation process.
Technical Assistance: Cerebra offers technical support during the onboarding phase to help new users resolve any issues they might encounter during the integration of mPass with their existing systems.
Comprehensive Documentation: mPass provides detailed user manuals and implementation guides. These resources are designed to help IT teams and administrators understand the features, customization options, and deployment strategies for the MFA solution.
Knowledge Base: The company maintains an online repository with FAQs and troubleshooting guides, making it easier for users to self-resolve common issues.
24/7 Customer Support: mPass offers round-the-clock technical support through various channels such as email, phone, and live chat. This ensures that any issues users face can be addressed quickly and efficiently.
Dedicated Account Manager: In some cases, enterprises might be assigned a dedicated account manager to help address specific concerns and provide ongoing support.
Online Training: mPass offers webinars or online sessions to train IT administrators and end-users on how to use the product effectively. These sessions cover best practices for MFA setup, policy management, and user management.
On-Site Training: For large organizations, on-site training may be available, where the mPass team can directly engage with your employees to ensure proper deployment and usage of the solution.
Proactive Monitoring: In some cases, the support team may offer proactive monitoring services to ensure the mPass system functions optimally, addressing any potential issues before they become critical.
mPass security measures process:
Multifactor Authentication (MFA): The core functionality of mPass is to provide additional layers of authentication beyond just passwords, significantly enhancing security against fraud, phishing, and password-related attacks.
Encryption: mPass uses fully encrypted communication between the application and the user's device, particularly for Push Authentication, which helps protect against Man-in-the-Middle attacks.
Out-of-Band Authentication: For Push Authentication, mPass requires the user's mobile device to be connected to the internet to receive notifications, adding an extra layer of security by preventing unauthorized access attempts when the user is not connected.
Compliance with OATH Standards: mPass supports leading standards for secure OTP (One-Time Password) generation by complying with OATH (Initiative for Open Authentication) standards.
Multiple Verification Channels: The system offers various channels for delivering additional verification factors, including SMS, Mobile App Push Notifications, Soft Tokens on iOS & Android, and Email, allowing for flexible and secure authentication methods.
Secure User Registration: mPass provides multiple options for user registration, allowing administrators to choose the most secure method based on their preferences and enrollment plans.
Policy-Based Authentication: The system allows for the creation of effective policies to handle user authentication, enabling organizations to control authentication and validation requests based on various criteria parameters.
Enterprise-Grade Deployment: mPass supports deployment of multiple authentication servers in redundant mode, ensuring high availability and reducing the risk of system-wide failures.
Secure Integration: The solution offers wide integration options with enterprise applications through a set of APIs, Agents, and Services, allowing for secure connections with existing systems.
Robust Risk Management: mPass includes features for risk mitigation, such as temporary or emergency authenticators that can be used to deactivate MFA functionality in specific systems or applications when necessary.
Regular Updates: mPass releases updates regularly, which can include security patches, bug fixes, performance improvements, and new features. The exact frequency of these updates is not specified, but regular updates are a common practice in cybersecurity software to address emerging threats and vulnerabilities.
The data ownership and portability policy for mPass (by Cerebra) typically includes several key aspects related to control, access, and transferability of user data. Based on general industry standards for SaaS-based security platforms like mPass, the policy would generally address the following:
Customer Ownership: The client (organization using mPass) retains full ownership of any data collected, managed, or processed by the mPass system. This includes user authentication records, system logs, and any personal or sensitive data.
Cerebra’s Role: As the service provider, Cerebra would not claim ownership over the client’s data but act as the data processor. Their role is to safeguard and manage the data according to the terms of the service agreement.
Export Options: Customers are usually granted the ability to export their data at any time. This may include exportable reports, logs, or user data in standard formats such as CSV or JSON, making it easier to transfer data to other systems if necessary.
Service Transition: When terminating the service, mPass likely allows for a data export option that lets clients transfer their authentication and user data to another system or backup.
No Vendor Lock-In: Policies usually aim to avoid vendor lock-in, ensuring clients can seamlessly transition their data if they decide to stop using mPass.
Retention Policy: Cerebra would define a retention period for data after the termination of the contract, after which the data would be securely deleted unless otherwise requested by the client.
For mPass (by Cerebra), the terms and conditions for contract renewal and cancellation are likely to align with general SaaS industry standards. Below are typical aspects that you might expect in such agreements:
Automatic Renewal: Contracts may automatically renew for a subsequent period (often one year) unless the customer provides written notice of non-renewal within a specified timeframe (e.g., 30 or 60 days before the current term ends).
Manual Renewal: Some agreements may require manual renewal, where the client must confirm their intent to renew the subscription, often accompanied by a review of pricing or service terms.
Notification: mPass would likely notify the customer before renewal, giving them time to review the contract and make necessary adjustments.
Cancellation Window: Contracts typically include a notice period for termination (e.g., 30 days), allowing either party to cancel without penalty if notice is given within the agreed-upon timeframe.
Early Termination Fees: If the client cancels before the end of the contract term, there may be early termination fees or a requirement to pay the remainder of the contract.
Prorated Refunds: In some cases, if the service is canceled mid-term, a prorated refund may be available for unused services, although this can vary based on the terms.
Data Access Post-Cancellation: Upon cancellation, mPass would likely grant customers a limited time to access and export their data before the account is fully terminated and data is purged.