How your sign-in is protected
What the product does on every account, without anybody switching it on, and what you can add.
Steps
- Sign-in is rate-limited and locks after repeated failures; every attempt, successful or not, is recorded with its device, location and address, and you can read your own record under Sign-in history.
- A session is tied to a device. Each is listed under Sessions and can be ended from there; sessions also expire on their own after inactivity (Your session has expired. Sign in again to continue.).
- Two-factor authentication is yours to turn on under Two-factor authentication: a code from an authenticator app, or a one-time code by email, with recovery codes for a lost phone.
- Your workspace is its own database, reached only at its own address. Every action is checked against your permissions on the server; a screen that is hidden from you is also refused to you.
- Cards are entered into the payment provider’s own fields. SISC keeps only the brand and the last four digits.
Related
Was this page helpful?
Thank you.
Your answer is kept on this device only. Nothing is sent anywhere — there is no service behind this button yet, and this page will say so until there is.