Security guide
Protect and recover your account
Use verified email, strong credentials, and deliberate session controls.
Last updated September 24, 2026
What to know
Use a unique password of at least 12 characters, verify the account email, and revoke other sessions after a credential concern. Password reset links are single-use and expire. Support will never ask for your password, reset token, OAuth token, or payment-card details.
Do this
- 1. Verify your email.
- 2. Use a unique password and password manager.
- 3. Revoke other sessions after suspected exposure.
- 4. Never send secrets or unredacted workspace exports to support.