Security

Protect your account with strong authentication and session management.

Password

If you signed up with email/password (not OAuth), you can change your password here.

Changing Your Password

  1. Go to Settings → Security
  2. Click Change Password
  3. Enter your current password
  4. Enter and confirm your new password
  5. Click Update Password

Password Requirements

  • Minimum 8 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number
  • At least one special character (recommended)

Tip: Use a password manager to generate and store strong, unique passwords.

Two-Factor Authentication (2FA)

Add an extra layer of security with two-factor authentication. When enabled, you'll need both your password and a code from your phone to log in.

Enabling 2FA

  1. Go to Settings → Security
  2. Click Enable Two-Factor Authentication
  3. Scan the QR code with an authenticator app:
    • Google Authenticator
    • Authy
    • 1Password
    • Microsoft Authenticator
  4. Enter the 6-digit code from the app
  5. Save your backup codes (store securely!)
  6. Click Enable

Important: Save your backup codes in a secure location. If you lose access to your authenticator app, backup codes are the only way to recover your account.

Disabling 2FA

  1. Go to Settings → Security
  2. Click Disable Two-Factor Authentication
  3. Enter a code from your authenticator app (or a backup code)
  4. Confirm disabling

Backup Codes

Backup codes let you access your account if you lose your authenticator app.

  • You receive 10 backup codes when enabling 2FA
  • Each code can only be used once
  • Store them securely (password manager, printed in a safe)
  • Generate new codes anytime (invalidates old ones)

Regenerating Backup Codes

  1. Go to Settings → Security
  2. Click View Backup Codes
  3. Enter your password or 2FA code
  4. Click Generate New Codes
  5. Save the new codes securely

Active Sessions

View all devices and browsers where you're currently logged in.

Session information includes:

  • Device type (desktop, mobile, tablet)
  • Browser name and version
  • Operating system
  • IP address and location (approximate)
  • Last activity time

Revoking Sessions

If you see an unfamiliar session or want to log out from other devices:

  • Revoke one session: Click "Sign Out" next to the session
  • Revoke all sessions: Click "Sign Out All Other Devices"

Security tip: If you see sessions you don't recognize, immediately change your password and enable 2FA.

Login History

Review recent login attempts to your account:

StatusInformation Shown
SuccessfulTime, device, location, method (password, OAuth, magic link)
FailedTime, device, location, failure reason

Login history is kept for 90 days. Business plan customers have access to extended audit logs.

Account Recovery

If you're locked out of your account:

Forgot Password

  1. Click "Forgot Password" on the login page
  2. Enter your email address
  3. Check your email for a reset link
  4. Create a new password

Lost Authenticator App

  1. Use one of your backup codes
  2. Go to Settings → Security
  3. Disable 2FA
  4. Re-enable with your new authenticator app

Lost Both Password AND 2FA

  1. Contact support at support@brightsea.ca
  2. Provide account verification information
  3. Identity verification may take 1-3 business days

How We Protect Your Data

  • • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • • Passwords hashed with bcrypt + salt
  • • Infrastructure hosted on AWS with SOC 2 compliance
  • • Regular security audits and penetration testing
  • • Automatic logout after 30 days of inactivity
  • • Rate limiting on login attempts to prevent brute force

See our Privacy Policy and Terms of Service for more details.