Provisioned accounts (synthetic phase): Sam Svoboda · Brad Brabec — passwords as set by Sam, not displayed here. Try a wrong password to see failure and lockout behavior; recovery works too.
Password recovery
Enter your account ID. If it exists, a single-use recovery code is sent to the address on file. The response looks identical either way — accounts can't be discovered from this screen.
Reset password
In this demo the “emailed” code is shown below. It expires in 15 minutes and works exactly once.
Session started · idle timeout 30 min · absolute limit 12 h · previous sessions unaffected until you sign out everywhere.
SYNTHETIC DEMO — NO REAL ACCOUNTS
Beacon · every control on this screen has a matching enforced contract in the foundation kernel (auth.py: scrypt-hashed passwords, uniform failure responses, lockout, hashed single-use recovery tokens, session rotation & expiry).