Account and security
Protect accounts, sessions and private workspace data
Use 2FA, careful role management and safe support practices to reduce account risk.
7 minute read All usersUpdated 15 August 2026
On this page
Quick answer
Use a unique password or trusted sign-in provider, enable TOTP two-factor authentication, remove unused access and never share passwords, recovery links, authentication codes, API keys or card details.
Enable two-factor authentication
- Open Your account, then Account and security.
- Start two-factor setup and scan the QR code with a trusted authenticator app.
- Enter the current verification code to complete enrolment.
- Keep access to the authenticator app. The current TOTP setup does not issue backup codes.
Respond to suspicious activity
- Reset the password through the secure recovery flow if the account uses a password.
- Use Sign out other devices from Account and security.
- Review connected sign-in providers and workspace membership.
- Contact support from the account email with the approximate time and visible activity. Do not send credentials or authentication links.
Private workspace and file access
Database and storage access is scoped to authorised workspace membership. Private files are delivered through short-lived signed URLs. API keys are company-scoped and stored as hashes. Admin actions should remain restricted and auditable.
Still need help?
Continue with the assistant or support team
The in-app assistant can explain the page you are using. For an account-specific problem, send support the expected result, reproduction steps and any safe request or job ID.
