How Google Sign-In works
- You begin on a VÖRSANN page at
vorsann.store. - Your browser is redirected to Google at
accounts.google.com. - Google handles the password, account recovery and any 2FA challenge.
- Google returns a limited identity assertion to VÖRSANN.
- VÖRSANN checks whether that identity is approved for an organization, program and case.
VÖRSANN does not receive your Google password or 2FA code.
Service relationships
Operates the application, approves users and controls workspace permissions.
Acts as the identity provider on Google-controlled pages. Google authentication is not operated by VÖRSANN.
Provide application-hosting and database infrastructure used by VÖRSANN.
Recognize a legitimate flow
- The VÖRSANN page uses HTTPS on
vorsann.store. - The Google identity screen uses HTTPS on
accounts.google.com. - Do not paste or forward callback URLs containing
code=, session cookies or tokens. - Stop if a page asks you to send a password or 2FA code directly to VÖRSANN.
Security controls
Controlled workspaces use server-side sessions, restricted database credentials, permission checks, audit events, no-store responses and noindex controls. Access may be disabled during security review or maintenance. These controls reduce risk but do not make any internet service risk-free.
Report a concern
Use the contact page or the published security.txt. Include the affected URL and what you observed. Never send live passwords, 2FA codes, OAuth codes, database credentials, access tokens or private evidence.