AI PoweredIAM Access Control

RecoveryCodes

RecoveryCodes inventories MFA authenticators and recovery codes for accounts that identity providers and password vaults cannot reach: root accounts, registrars, banks, and vendor portals.

RecoveryCodes is an iam access control platform, priced at 49 €/month on the Inventory plan, integrating with Google, GitHub, GitLab, and OIDC. InnovaAI scores it 6.9/10 for agency resale.

Consider6.9/10

Agency Audit

RecoveryCodes maps MFA authenticators and recovery codes to accounts outside identity providers (root accounts, registrars, banks, vendor portals), then exports audit evidence for compliance and offboarding workflows. It's built for security consultancies, MSSPs, and IT service providers who need to inventory and report on MFA coverage that Okta, Entra, and password vaults cannot see. Agencies can resell this as a compliance retainer to clients requiring ISO 27001 attestation or offboarding documentation. The Compliance plan (149 € monthly) includes exportable coverage reports, offboarding workflows, and audit retention, the core deliverables for a managed security retainer.

ConsiderNo WLTiered
Fit

6.9/10

Typical Margin

67%

Time-to-Value

1d about a day

Complexity
Low
Consider
Fit69
Visit RecoveryCodes
Best For
  • Your clients undergo ISO 27001 or SOC2 audits and need dated, exportable MFA coverage reports showing 2FA status per account outside their identity provider.
  • You manage offboarding workflows for clients with shared accounts (registrars, root accounts, founder accounts) and need attestation evidence that MFA was transferred before access revocation.
  • You serve financial services, SaaS, or regulated tech clients who must prove MFA protection on non-federated accounts like bank portals and vendor integrations.
Not For
  • Your clients only use federated identity (Okta, Entra, Okta) for all accounts; RecoveryCodes adds no value if there are no unmanaged accounts to inventory.
  • You need white-label branding for client-facing portals; RecoveryCodes does not offer a verified white-label program and client surfaces display the RecoveryCodes brand.
  • Your clients require HIPAA, PCI-DSS, or FedRAMP compliance; RecoveryCodes does not publish compliance certifications beyond EU data residency.

Profit Path

Your Cost (EUR)

49 €/mo

Market Range

$199–$499/mo

Revenue Model

Monthly Recurring

Planning benchmark at United States price levels. Not a measured market survey.

Platform Features

Core capabilities of RecoveryCodes

Unlimited account and authenticator inventory

Map every account (root, registrar, bank, vendor portal) to its assigned authenticators without limit. Agencies can track all client accounts in one workspace and assign status labels (protected, one-device risk, no 2FA) to identify coverage gaps for compliance reporting.

Reverse lookup by authenticator

Query a single phone, security key, or backup code to see all accounts it protects. When a client loses a device or an employee departs, agencies instantly identify which accounts need re-enrollment before disabling the authenticator.

Recovery codes per domain

Store recovery codes separately from password vaults without holding TOTP seeds. Agencies can share selected domains with approved team members, with every reveal requiring step-up authentication and audit logging for compliance evidence.

Exportable MFA coverage reports

Generate dated reports showing 2FA status and authenticator enrollment for every account. Agencies deliver these directly to auditors or include them in compliance attestations without manual spreadsheet assembly.

Offboarding attestation workflow

Document that MFA was transferred to remaining team members before access is revoked. Produces dated, exportable evidence for departing-user compliance and reduces outage risk from lost authenticators.

Audit log with 90-day retention (Inventory) or extended retention (Compliance)

Track all access and changes to accounts, authenticators, and recovery codes. Agencies use audit logs to prove who accessed sensitive accounts and when, satisfying ISO 27001 and SOC2 evidence requirements.

What Makes RecoveryCodes Different

Unique advantages vs similar tools in this niche

Maps accounts outside the IdP to authenticators and recovery codes

vs Identity providers like Okta and Entra that only cover federated apps

The tool explicitly targets root accounts, registrars, banks, and vendor portals that IdPs cannot report on.

Reverse lookup for authenticator changes

vs Manual tracking in spreadsheets or memory

When a phone or security key changes, the tool lists all accounts that need re-enrollment.

Offboarding attestation with audit trail

vs Ad-hoc processes that leave blind spots

Provides dated, exportable proof that access was transferred before account removal.

Investment ROI Calculator

Value equation analysis for RecoveryCodes, based on the Hormozi framework

What is the Hormozi framework? A four-factor score: (what the service delivers × how reliably it delivers) divided by (how long it takes × how much effort it requires). A higher Value Multiplier means a better return on the time and money invested: faster, easier, and more proven results.

Value MultiplierExceptional

3.9× value multiple: invest 49 €/mo and agencies typically charge $199–$499/mo for the work it powers.

Outcome35
÷
Friction9

Why This Succeeds

Higher is better

Implementation Challenges

Lower is better

Strong ROI. RecoveryCodes at 49 €/mo supports market rates of $199–$499. Its 3.9× value-equation score weighs client outcome and likelihood against the time and effort to deliver, not cost.

Best if:Your clients undergo ISO 27001 or SOC2 audits and need dated, exportable MFA coverage reports showing 2FA status per account outside their identity provider.You manage offboarding workflows for clients with shared accounts (registrars, root accounts, founder accounts) and need attestation evidence that MFA was transferred before access revocation.You serve financial services, SaaS, or regulated tech clients who must prove MFA protection on non-federated accounts like bank portals and vendor integrations.You want to offer a compliance-focused retainer without building custom inventory tooling; the Compliance plan includes offboarding workflows and email/webhook alerts for risk detection.

Pricing

RecoveryCodes platform cost to your agency

~67% margin

Starts at 49 €/mo (Inventory), scales to 149 €/mo (Compliance)

Inventory

49 €/mo
39 €/mo annually
  • Unlimited account and authenticator inventory
  • Reverse lookup for every authenticator
  • Track recovery codes per domain
  • Status labels: protected, one device risk, no 2FA

Compliance

149 €/mo
119 €/mo annually
  • Dated, exportable offboarding attestation
  • Dated, exportable coverage and risk reports
  • Extended audit retention
  • Offboarding workflow before access is removed
Enterprise

Enterprise

Custom
  • Customer managed encryption keys through KMS
  • SAML, SCIM, and LDAP enforcement
  • Self hosting option
  • Defined SLA

No verified white-label program for RecoveryCodes: client-facing delivery runs under the platform's native branding.

Prices as published by the vendor in EUR · your regional price may differ

Market Intelligence

How agencies monetize RecoveryCodes: real offer economics and market positioning

Service Applications
Reporting & AnalyticsAutomation & IntegrationsClient OnboardingDelivery & Production
Best For
  • Security consultancies
  • Managed security service providers (MSSPs)
  • IT service providers
Not Ideal For
  • Agencies without security or compliance focus
  • Agencies serving only small local businesses without MFA needs

Service Retainer

ai-powered

Agency charges monthly retainer for managed service. Fee varies by client size and scope.

Offer Economics: What You Charge vs. What It Costs

Margin includes platform cost + agency labor at $75/hr.

RecoveryCodes SMB Starterlocal smb

Local small businesses with 5-20 vendor and SaaS accounts needing basic MFA inventory and recovery code tracking

$540/mo
Tool: 49 €/moLabor: 2h/mo × $75 = $150Margin: 63%Benchmark: $199–$499/mo
Set up RecoveryCodes workspace and map all client vendor, registrar, and bank accounts to authenticatorsConfigure status labels and flag any accounts with no 2FA or single-device riskDocument recovery codes per domain and deliver a secure handoff record to clientMonitor monthly for new account additions and update inventory with status report
RecoveryCodes Growth Shieldgrowth smb

Funded startups and 10-50 employee companies managing multiple SaaS stacks, vendor portals, and team offboarding cycles

$790/mo
Tool: 49 €/moLabor: 4h/mo × $75 = $300Margin: 56%Benchmark: $499–$1.2K/mo
Deploy RecoveryCodes Compliance workspace with OIDC SSO and member role configuration for client teamBuild full account-to-authenticator inventory with reverse lookup coverage across all critical domainsConfigure webhook and email alerts for risk events and sensitive access changesDeliver monthly coverage and risk report with offboarding attestation for any departing team members
RecoveryCodes Compliance Managedmid market

Mid-market companies with 50-500 employees requiring audit-ready MFA coverage reports, offboarding workflows, and compliance evidence for SOC 2 or ISO audits

$1.5K/mo
Tool: 49 €/moLabor: 8h/mo × $75 = $600Margin: 57%Benchmark: $1.2K–$3K/mo
Configure RecoveryCodes Compliance plan with extended audit retention, OIDC SSO, and role-based workspace for client IT and security teamsIntegrate webhook alerts into client's existing incident or ticketing workflow for real-time risk notificationsOptimize and maintain full account inventory with quarterly reverse-lookup audits and gap remediationProduce dated, exportable offboarding attestations and coverage reports formatted for auditor submission
RecoveryCodes Enterprise ProgramenterpriseHIGH MARGIN

Enterprise organizations with 500+ employees requiring SAML/SCIM enforcement, KMS encryption, self-hosted deployment, and continuous compliance evidence across complex multi-team environments

$4.5K/mo
Tool: 49 €/moLabor: 16h/mo × $75 = $1.2KMargin: 72%Benchmark: $3K–$10K/mo
Deploy and configure RecoveryCodes Enterprise with SAML, SCIM, and LDAP enforcement integrated into client identity infrastructureSet up customer-managed KMS encryption and coordinate self-hosting deployment within client's environmentBuild and maintain complete cross-department MFA inventory with defined SLA monitoring and custom data retention policiesDeliver quarterly compliance evidence packages including dated coverage reports, offboarding attestations, and audit log exports for security and legal review

Scale Economics: Based on Starter Offer

Using RecoveryCodes SMB Starter at $540/client. Platform: 49 €/mo. Labor: 2h/client × $75/hr.

5 clients
$2.7K
MRR
$1.9K net (70%)
10 clients
$5.4K
MRR
$3.9K net (71%)
20 clients
$10.8K
MRR
$7.8K net (72%)

Net = MRR - platform cost - labor (2h/client × $75/hr).

Weighted Avg Margin
67%
Across all offer tiers, incl. labor at $75/hr
Run your agency audit

Investment Decision Framework

Strategic vetting analysis for RecoveryCodes

Vetting Verdict

Consider

Favorable fit, worth a closer look

Agency Fit(white-label + resell pathway)
69/100
0255075100
Resell Friction(WL + mode + complexity)
50/100
0255075100

Buy If

4
OPERATIONAL FIT

Your clients undergo ISO 27001 or SOC2 audits and need dated, exportable MFA coverage reports showing 2FA status per account outside their identity provider.

OPERATIONAL FIT

You manage offboarding workflows for clients with shared accounts (registrars, root accounts, founder accounts) and need attestation evidence that MFA was transferred before access revocation.

OPERATIONAL FIT

You serve financial services, SaaS, or regulated tech clients who must prove MFA protection on non-federated accounts like bank portals and vendor integrations.

OPERATIONAL FIT

You want to offer a compliance-focused retainer without building custom inventory tooling; the Compliance plan includes offboarding workflows and email/webhook alerts for risk detection.

Skip If

4
CAUTION

Your clients only use federated identity (Okta, Entra, Okta) for all accounts; RecoveryCodes adds no value if there are no unmanaged accounts to inventory.

CAUTION

You need white-label branding for client-facing portals; RecoveryCodes does not offer a verified white-label program and client surfaces display the RecoveryCodes brand.

CAUTION

Your clients require HIPAA, PCI-DSS, or FedRAMP compliance; RecoveryCodes does not publish compliance certifications beyond EU data residency.

CAUTION

You operate in a non-EUR timezone and need local support; RecoveryCodes is made and hosted in the EU with no documented multi-region deployment option.

Bottom Line

RecoveryCodes maps MFA authenticators and recovery codes to accounts outside identity providers (root accounts, registrars, banks, vendor portals), then exports audit evidence for compliance and offboarding workflows. It's built for security consultancies, MSSPs, and IT service providers who need to inventory and report on MFA coverage that Okta, Entra, and password vaults cannot see. Agencies can resell this as a compliance retainer to clients requiring ISO 27001 attestation or offboarding documentation. The Compliance plan (149 € monthly) includes exportable coverage reports, offboarding workflows, and audit retention, the core deliverables for a managed security retainer.

Reality Check

Trade-offs & Gotchas

RecoveryCodes does not store TOTP seeds or act as a shared authenticator app, so it cannot replace Authy or Google Authenticator for team-wide login. Agencies must educate clients that this is an inventory and emergency record tool, not a replacement for their existing MFA stack. Setup requires manual account enrollment per domain, which scales linearly with client account count.

Implementation Reality

Low effort: self-service setup with guided onboarding

Effort: 3/10Time: 3/10

Academy for RecoveryCodes

Work through it in order: the course for this service first, then the modules behind it.

Core concepts

The mental model you need to price and scope the work.

  1. Non-Human Identity PerimeterConcept

    The Non-Human Identity Perimeter framework reframes IAM for agencies: every AI agent, API key, and service account is an identity that must be governed with the same rigor as a human employee. As agencies deploy agents for content, reporting, and client communication, each one becomes a potential entry point. A single misconfigured credential can expose client data or trigger compliance failures. The framework urges agencies to inventory all non-human identities, assign ownership, and enforce least-privilege access. For example, when Meta's ad AI altered approved creative post-launch, it highlighted how platform agents operate outside traditional human access controls. Tools like Zluri and Securden now offer dedicated non-human identity governance, while 1Password extends vaults to AI agents. Agencies that ignore this perimeter risk client trust and regulatory penalties.

  2. Identity Blast RadiusConcept

    Identity Blast Radius is a framework for sizing the potential damage of a single compromised credential or misconfigured access path. For agencies, the blast radius is not just the client's data but the agency's own reputation and compliance posture. A single breach from weak credential management can collapse client trust, as the category description warns. The framework forces agencies to map every identity, human or non-human, to the resources it can reach, then measure the worst-case outcome if that identity is compromised. Consider an agency using Okta for SSO and 1Password for secrets: if a shared vault credential is exposed, the blast radius includes every client project that vault touches. The goal is to shrink the radius by enforcing least privilege, segmenting access, and rotating credentials, turning a potential catastrophe into a contained incident. Recent agentic AI incidents, where autonomous agents posted thousands of messages or altered approved creative, expand the blast radius to non-human identities, making this framework essential for modern agency security.

  3. Access Surface RatioConcept

    The Access Surface Ratio framework measures the total number of access pathways an agency manages (human logins, API keys, AI agent credentials, machine identities) against the number of actual resources those pathways protect. A high ratio means many identities point to few critical assets, amplifying breach risk. Agencies often accumulate unused SaaS accounts, stale service accounts, and over-provisioned AI agent permissions, inflating the surface without adding value. For example, a recent incident where an AI agent swarm posted 18,000+ messages externally shows how ungoverned non-human identities can act at scale. Tools like Zluri or Securden help discover and govern these identities, but the framework urges agencies to calculate their own ratio: list every identity, map it to resources, and eliminate orphaned access. Lowering the ratio reduces client compliance exposure and simplifies audits.

8 modules selected for RecoveryCodes

Frequently Asked Questions

Answers about pricing, setup, implementation

RecoveryCodes inventories MFA authenticators and recovery codes for accounts outside identity providers (root accounts, registrars, banks, vendor portals). It performs reverse lookups to show which accounts a specific authenticator protects, generates MFA coverage reports for compliance, and produces offboarding attestation evidence when employees depart. Agencies use it to audit and report on MFA protection that Okta, Entra, and password vaults cannot see.

RecoveryCodes offers 3 pricing tiers, starting at 49 €/mo (Inventory) up to 149 €/mo (Compliance). Agencies typically achieve 67% profit margins when reselling to clients.

No verified white-label program. Client-facing surfaces display the RecoveryCodes brand, so you cannot present a fully branded portal to end clients. You can resell the tool as a managed service under your own service name, but the interface itself will show RecoveryCodes branding.

RecoveryCodes supports Google and GitHub as identity providers via OIDC integration. This allows agencies to provision workspace members and enforce role-based access using client Google Workspace or GitHub org credentials. Native integrations also include SAML, SCIM, and LDAP for enterprise identity systems.

Initial workspace setup takes 15-30 minutes. Adding each client account requires manual enrollment per domain (entering the account name, assigned authenticators, and recovery codes). Reverse lookup and reporting are available immediately after enrollment. Setup time scales with the number of unmanaged accounts the client maintains outside their identity provider.

Security consultancies, managed security service providers (MSSPs), IT service providers, and compliance-focused agencies. Best suited for clients in regulated industries (financial services, SaaS, healthcare tech) who must prove MFA protection on non-federated accounts and need audit evidence for ISO 27001, SOC2, or similar compliance frameworks.

No. RecoveryCodes stores recovery codes only, not TOTP seeds or shared login codes. It functions as an inventory and emergency record, not a replacement for Authy, Google Authenticator, or other team authenticator apps. This design prevents RecoveryCodes from becoming a single point of failure for live MFA.

RecoveryCodes does not publish a data retention or export policy in available documentation. Before signing clients onto a retainer, contact RecoveryCodes directly to confirm whether exported inventory and audit logs remain accessible after cancellation, and whether the tool supports bulk export for migration.