Securing Your Account
Two-factor sign-in, and encrypting the data we send you.
Two-factor sign-in, and encrypting the data we send you.
Steps
Two layers
There are two different security settings worth knowing about — one protects your login, the other protects the data we send out.
Protecting your login
Open the Security section in Settings. Two-factor means a code from your phone on top of your password.
Why bother
This account can place calls and charge your card, so it's worth the extra ten seconds at sign-in. Enable starts the setup.
How setup goes
You confirm your password, scan a QR code with an authenticator app, and type one code back to prove it worked.
Save the backup codes
You'll be given backup codes at the end. Save them somewhere that isn't your phone — they're how you get back in if you lose it.
The other layer
The Security page is separate, and it's about your data rather than your login.
Encrypting what we send
Turn this on and every payload we send to your system is encrypted with a key only your organisation holds. If you're handling health data, this is the one you want.
The key is shown once
Like an API key, you see the encryption key exactly once. Download the backup when it's offered — your system needs it to read anything we send.