Secure your account
Set up two-factor authentication, review sessions, and keep server credentials and API keys under control.
On this page
Enable two-factor authentication
Open Account and follow the two-factor setup flow with your authenticator app. Save the recovery codes somewhere secure and separate from your normal sign-in device.
Accounts with two-factor authentication use email and password plus the second factor. If you previously signed in through Google or GitHub, follow the password setup or reset flow so you can use this sign-in path.
Review sessions and account access
Review active sessions and revoke devices you no longer use. Data Hall sends a notice for a sign-in from a new kind of device; investigate one you do not recognize.
Keep your email account secure. An email change requires confirmation through the current address and verification of the new one.
Keep secrets out of shared channels
Generated server credentials and API keys are shown once. Save them in a secure location when revealed. A lost server credential can be replaced through Access; a lost API key should be revoked and replaced.
Use individual team accounts instead of sharing a login. Review access when someone leaves and revoke any API keys or server SSH keys that should no longer be used.
You control the guest operating system and application security: updates, firewall rules, software configuration, application credentials, and data access.
Keep going
Need help with your environment? Contact Support.