Your Structurell account opens every subscription you belong to, so it is worth a few minutes to make sure it is well protected. All of your sign-in settings are in one place: open the user menu in the top right of the Portal and select **Account**. This article gives an overview of each protection and links to the detailed guides.

Your account settings have four tabs:

- **Account**: your name, email address, language and photo.
- **Password**: change your password.
- **Sign-in methods**: two-factor authentication and passkeys.
- **Sessions & devices**: where you are signed in, and devices you have chosen to remember.

## A quick security checklist

1. **Add a passkey.** A passkey lets you sign in with your fingerprint, face or device PIN instead of a password and code, and cannot be phished like a password. See [Logging in and using passkeys](/getting-started/logging-in).
2. **Use an authenticator app for two-factor codes.** Two-factor authentication is always on. Email codes are the default; an authenticator app is safer because it does not depend on your inbox. See [Setting up two-factor authentication](/getting-started/two-factor-authentication).
3. **Keep your recovery codes safe.** If you use an authenticator app, store your 8 recovery codes in a password manager or another safe place.
4. **Use a strong, unique password.** At least 8 characters, and not one you use anywhere else. See [Changing or resetting your password](/getting-started/resetting-your-password).
5. **Review your sessions and remembered devices** every so often, as described below.

## Confirming it's you

Some changes are sensitive, so the Portal asks you to prove it is really you before making them, even though you are already signed in. When you change your password or your email address, a **Confirm it's you** window opens. Under **How do you want to confirm?**, choose one of the methods your account has:

- **Passkey**
- **Code from your authenticator app**
- **Code sent to your current email address**
- **Your current password**

Then select **Confirm** (or **Use passkey**). This stops someone who finds your computer unlocked from taking over your account.

## Check where you are signed in

1. In **Account**, select the **Sessions & devices** tab.
2. The **Signed-in sessions** panel lists every place your account is signed in, such as each browser and the iOS app. The one you are using now is marked **Current session**. Each entry can show the browser and device, when it was last active and, where available, an approximate location.
3. To sign out one session, select **Log out** next to it and confirm.
4. For several at once, open the actions menu (the three dots) at the top of the panel and choose **Log out other sessions**, **Log out all sessions** or **Log out older than 7 days**, then select **Confirm**.

**Log out other sessions** and **Log out all sessions** also forget your remembered devices.

## Check your remembered devices

When you sign in with a password and code, you can tick **Remember this device for 30 days** so that device is not asked for a code again for 30 days. The **Remembered devices** panel on the **Sessions & devices** tab lists these devices, with when each was remembered, last used and when it expires.

- Select **Forget** next to a device, then **Forget** again to confirm. It is asked for a two-factor code at its next sign-in. Nobody is signed out.
- To forget every device, open the actions menu at the top of the panel and select **Forget all**.

Remembered devices are also forgotten automatically when you change your password or two-factor method.

## Security emails

We email you whenever your password is changed, a passkey is added or removed, or your two-factor method changes. When someone asks to change your email address, we also write to your current address. These **Security Activity** emails are always sent and cannot be switched off. If you receive one you do not recognise:

1. Change your password straight away. See [Changing or resetting your password](/getting-started/resetting-your-password).
2. Select **Log out other sessions** on the **Sessions & devices** tab.
3. Check your passkeys and two-factor method on the **Sign-in methods** tab, and delete any passkey you do not recognise.
4. If an email change is waiting that you did not ask for, select **Cancel change** under your email address on the **Account** tab.
5. Tell your subscription administrator, or contact support.

## Signing out

To sign out of the browser you are using, open the user menu and select **Log Out**. On a shared or public computer, always log out when you finish, and do not tick **Remember me** or **Remember this device** there.

## Notes

- Structurell does not currently offer sign-in with Microsoft, Google or other identity providers.
- Two-factor authentication cannot be switched off.
- The Portal does not have a separate button to create new recovery codes. To get a fresh set, switch to email codes and then back to an authenticator app. See [Setting up two-factor authentication](/getting-started/two-factor-authentication).
- If you use the iOS app, you can also protect it with Face ID or Touch ID. See [Using the Structurell iOS app](/getting-started/the-ios-app).