Security
Protect your account with strong authentication and session management.
Password
If you signed up with email/password (not OAuth), you can change your password here.
Changing Your Password
- Go to Settings → Security
- Click Change Password
- Enter your current password
- Enter and confirm your new password
- Click Update Password
Password Requirements
- Minimum 8 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character (recommended)
Tip: Use a password manager to generate and store strong, unique passwords.
Two-Factor Authentication (2FA)
Add an extra layer of security with two-factor authentication. When enabled, you'll need both your password and a code from your phone to log in.
Enabling 2FA
- Go to Settings → Security
- Click Enable Two-Factor Authentication
- Scan the QR code with an authenticator app:
- Google Authenticator
- Authy
- 1Password
- Microsoft Authenticator
- Enter the 6-digit code from the app
- Save your backup codes (store securely!)
- Click Enable
Important: Save your backup codes in a secure location. If you lose access to your authenticator app, backup codes are the only way to recover your account.
Disabling 2FA
- Go to Settings → Security
- Click Disable Two-Factor Authentication
- Enter a code from your authenticator app (or a backup code)
- Confirm disabling
Backup Codes
Backup codes let you access your account if you lose your authenticator app.
- You receive 10 backup codes when enabling 2FA
- Each code can only be used once
- Store them securely (password manager, printed in a safe)
- Generate new codes anytime (invalidates old ones)
Regenerating Backup Codes
- Go to Settings → Security
- Click View Backup Codes
- Enter your password or 2FA code
- Click Generate New Codes
- Save the new codes securely
Active Sessions
View all devices and browsers where you're currently logged in.
Session information includes:
- Device type (desktop, mobile, tablet)
- Browser name and version
- Operating system
- IP address and location (approximate)
- Last activity time
Revoking Sessions
If you see an unfamiliar session or want to log out from other devices:
- Revoke one session: Click "Sign Out" next to the session
- Revoke all sessions: Click "Sign Out All Other Devices"
Security tip: If you see sessions you don't recognize, immediately change your password and enable 2FA.
Login History
Review recent login attempts to your account:
| Status | Information Shown |
|---|---|
| Successful | Time, device, location, method (password, OAuth, magic link) |
| Failed | Time, device, location, failure reason |
Login history is kept for 90 days. Business plan customers have access to extended audit logs.
Account Recovery
If you're locked out of your account:
Forgot Password
- Click "Forgot Password" on the login page
- Enter your email address
- Check your email for a reset link
- Create a new password
Lost Authenticator App
- Use one of your backup codes
- Go to Settings → Security
- Disable 2FA
- Re-enable with your new authenticator app
Lost Both Password AND 2FA
- Contact support at support@brightsea.ca
- Provide account verification information
- Identity verification may take 1-3 business days
How We Protect Your Data
- • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- • Passwords hashed with bcrypt + salt
- • Infrastructure hosted on AWS with SOC 2 compliance
- • Regular security audits and penetration testing
- • Automatic logout after 30 days of inactivity
- • Rate limiting on login attempts to prevent brute force
See our Privacy Policy and Terms of Service for more details.