NorthLedger Case CRM

Client case files. Treated like case files.

This console never stores seed phrases, private keys or exchange credentials. Intake that contains one is refused rather than saved — the same rule the public site promises clients.

Sign in

Use your NorthLedger account.

Accounts are created by the owner. There is no sign-up: a new account cannot read anything until it is activated. Clients are emailed, never given a login.

Second factor

Enter the 6-digit code from your authenticator app.

Codes are single-use and expire in 30 seconds.

Checked by Supabase against the TOTP factor enrolled on this account. A wrong code is refused here, not in the browser.

No second factor

This account signed in with a password alone.

No TOTP factor is enrolled, so there was no second factor to check. Enrolment is not built yet — until it is, this console is one stolen password away from a stranger, and it holds the contact details of people who have already been targeted once.

Enable MFA in Supabase → Authentication → MFA, then enrol each account. Step 5 of DEPLOY.md.