Skip to content

Settings & Security

Audience: All client users (for your own profile, MFA, and notification preferences) · Where: Settings in the sidebar (/settings).

Overview

Settings is where you manage your personal account — your profile, your login security, and how you're personally notified. It has four tabs:

  •   General


    Your profile and two-factor authentication.

  •   Licenses


    What your organization owns and how much is used.

    Licenses & Credits

  •   Integrations


    Link your source-code provider for code review.

    Integrations

  •   Alerts


    Your personal notification preferences (covered below).

Profile

Under General → Profile, update your Email, Display Name, and Phone, then click Save changes. This is your personal profile, not organization-wide settings.

Two-factor authentication (MFA)

Two-factor authentication (2FA/MFA) adds a second step to sign-in — a rotating code from an authenticator app — so a stolen password alone can't get into your account. The Two-factor authentication panel shows whether you're Not enrolled or enrolled.

Enrolling

  1. Click Set up two-factor authentication.
  2. Scan the displayed QR code with a TOTP authenticator app (Google Authenticator, 1Password, Authy, etc.) — or type the secret in manually.
  3. Enter the 6-digit code the app generates to verify and finish enrollment.

Once enrolled, you'll be asked for a code from your authenticator each time you sign in.

Removing it

You can unenroll (remove) a factor from the same panel if you need to switch devices — then re-enroll with the new device.

Organization-enforced MFA

Some organizations require MFA. If yours does and you haven't set it up, the portal will send you to the enrollment screen before you can continue. If you're a newly invited user in such an org, complete enrollment first — then you'll reach your dashboard.

Alerts (your notifications)

Under the Alerts tab (/settings/alerts) you control how you personally get notified about assessments and attack-surface changes. This is per-user — it only affects your own notifications, and you only ever receive alerts for assessments and assets you have access to.

For each alert type (a new critical finding, an assessment completing, an ASM change, etc.) you have three switches:

Switch Behavior
In-app Show the alert in the in-app notification bell.
Email Also send it to your account email.
Mute Opt out of that alert type entirely (turning it on disables the other two).

Changes save as you toggle; the defaults are in-app on, email off, nothing muted.

Shared channels are admin-managed

Organization-wide alert rules and shared delivery channels (a shared email address, a Slack/webhook endpoint) are set up by owners/managers in the Administration → Alerts panel, not here. The Alerts tab shown here is only your personal preferences.

Tips

Protect your account

  • Enroll in MFA even if it isn't required — it's the single biggest protection for your account, and these are security findings you don't want to be.
  • Keep your authenticator app's backup/recovery method safe so you don't get locked out when you change phones.
  • Profile changes here affect only you; organization-wide settings (members, roles, SSO, API keys) live in the manager/owner Administration console.

Related: Getting Started · Licenses & Credits · Integrations