MFA coaching software: what it is and how to choose it
MFA coaching software: what it is and how to choose it

MFA coaching software is practice software for coaches that secures logins with multiple verification steps instead of just a password. Choose software with a separate account per user, real MFA and configurable access rights. During a trial period or demo, check at least three things: who can create an account, which MFA methods are available and what happens if you lose your phone.
In short:
- Using MFA in coaching software increases security because it combines at least two different verification categories, such as password and app code.
- During a trial period you should check whether all users have their own account, which MFA methods are available and what happens if a phone is lost.
- Access rights must be configurable per person, so that not everyone has access to everything, and keeping change logs is essential for accountability.
- For a secure practice, it is important that the data is hosted within the EU and that a signed processing agreement is in place.
- When implementing MFA, it is wise to have a recovery plan ready, for example with backup codes or an administrator reset, in case someone loses their phone.
Table of contents
- What does MFA mean in practice in coaching software?
- Why MFA matters for your practice under the GDPR
- Checklist: what to look for when choosing coaching software with MFA?
- Step by step: setting up and managing MFA in a small practice
- MFA in practice: portal, calendar and session notes
- What coaches often forget about MFA
- Why Exantur suits coaches who want to work securely and with GDPR awareness
- Sources
- Frequently asked questions
What does MFA mean in practice in coaching software?
MFA stands for multi-factor authentication: you prove your identity with more than one check. The European Data Protection Board distinguishes three categories that together form strong authentication.
- Something you know: a password or PIN, the basis everyone already knows.
- Something you have: your phone with a code via SMS or app, or a physical security key. An app code is usually safer than SMS, because SMS can be intercepted.
- Something you are: a fingerprint or facial recognition. Be careful with this, because biometric data is sensitive and requires additional safeguards.
A simple SMS code at login is often called "two-step verification". Real MFA combines at least two different categories, so for example a password AND an app code. For a coach who manages client records, session notes and payment details, that combination makes it much harder for an unauthorized person to get in, even if the password has leaked.
Why MFA matters for your practice under the GDPR
The GDPR applies to every organization, including a solo coach with a few clients. The European Data Protection Board explains that small organizations must comply with the same principles as large companies, and must be able to demonstrate that they do.
MFA combines at least two of the three authentication categories (something you know, something you have, something you are) and is recommended by the EDPB as a form of strong authentication. That protects the confidentiality of client data: only authorized people can access it. It also supports the integrity of your records, because with unique accounts you can see who changed something.
MFA is one measure, not a complete solution. You remain responsible yourself for retention periods, purpose limitation and keeping track of why you process certain data. Access rights per person, a log of changes and a processing agreement with your software provider remain necessary alongside MFA. You can find more about those full obligations in our GDPR checklist for coaches.

Checklist: what to look for when choosing coaching software with MFA?
A demo or trial period is the moment to test critically, not just to look at the appearance of the software. Go through these questions before you take out a subscription.
- Does everyone have their own account? Shared logins between fellow coaches are a risk and are advised against, also by the EDPB, which recommends unique identification per user.
- Which MFA methods are there? Ask whether there is only SMS, or also an app or security key, and what happens if you lose your phone.
- Can you set access rights per person? An assistant coach does not need to see all financial data, a fellow coach does not need all client records.
- Are there logs or an overview of who changed what? That helps with demonstrating accountability.
- Where is the data stored and is there a processing agreement? EU hosting and a signed agreement are important signals that the provider takes GDPR seriously.
- How does onboarding and support work? And can a client log in securely to their own portal without you having to arrange everything manually?
Pro tip: ask specifically during the demo about the recovery process for a lost phone: if the provider does not have a clear answer to that, it is a warning sign.
You can find more background on secure software and the associated GDPR obligations in our explanation of secure coaching software and on GDPR coaching software.
Step by step: setting up and managing MFA in a small practice
Setting up MFA does not have to be complicated, certainly not in a practice with a few people.
- Step 1: create a separate account for everyone who works with the software and make MFA mandatory, not optional.
- Step 2: briefly explain to clients how to log in to their own portal and why that extra step is there, so that it does not cause confusion.
- Step 3: put in place a recovery plan for when someone loses their phone, for example with backup codes or a reset by the administrator.
- Step 4: designate someone who periodically checks whether accounts are still correct, who has access and whether old accounts of departed employees have been removed.
For that last step you can use methods from ENISA, which offers tools and approaches for planning periodic security checks.
MFA in practice: portal, calendar and session notes
MFA must work without slowing down your work. Session notes with observations, insights and action points should only be visible to the coach who conducted the session, unless you deliberately share rights with a colleague. Therefore ask whether the software can restrict access to notes per program, as described in our explanation of session notes software.
With the client portal, it makes sense for the client to log in themselves with a light form of security, while sensitive actions such as invoicing or sharing documents warrant an additional check. Also ask how calendar integrations with Google Calendar, Outlook or Zoom handle access: a good integration does not require you to share your master password with an external system, but works via secure authorization.

What coaches often forget about MFA
In conversations with coaches it is striking that sharing passwords between colleagues still happens often, especially under time pressure. That seems practical, but it makes it impossible to see who made which change, and it increases the risk in the event of a stolen password.
A unique login with MFA per person takes a few extra seconds when logging in, but it provides clear accountability: you always know who has been where. MFA is not a miracle cure. It protects the front door, but you still need a policy for who may see which data and how long you keep it.
— Martijn
Why Exantur suits coaches who want to work securely and with GDPR awareness
The software is built around the coaching process itself, not as an adapted general system. Every coach and employee gets their own account, the software supports MFA and a processing agreement is available, which aligns with the questions from the checklist above.
Clients work in their own coaching client portal to view goals, complete check-ins and open documents, without you as a coach having to share everything manually. On top of that, organizations with multiple coaches get roles and rights per user, so that not everyone can automatically access all client records.
You can try Exantur free for 14 days. After the trial period, the chosen subscription continues automatically, unless you cancel in time. View the subscriptions and prices on the pricing page and start the trial period when you are ready.
Sources
Frequently asked questions
What is the difference between MFA and two-step verification?
Two-step verification is often a specific form in which you receive one extra code after your password, usually via SMS. MFA is broader: it combines at least two different categories, such as a password with an app code or a security key, as described by the EDPB.
Does MFA automatically make my coaching practice GDPR compliant?
No, MFA is one important measure, but not a complete guarantee. You remain responsible yourself for matters such as retention periods, purpose limitation and a processing agreement with your software provider, as the EDPB explains.
What happens if I lose my phone and use MFA?
Good software offers a recovery option, for example with backup codes you have saved in advance or a reset by an administrator. Always ask about this during a demo, before you start working with the software.
Does Exantur support multi-factor authentication?
Yes, Exantur supports MFA and gives every coach and employee their own account with configurable access rights. In addition, data is hosted within the EU and a processing agreement is available.
Should I use biometric authentication with coaching software?
That is not necessary and warrants extra caution, because biometric data is sensitive and requires strict safeguards around storage and purpose limitation. A password combined with an app code is a simpler and equally effective choice for most coaching practices.
