Security, privacy and data
Protect your Scriboflow account
Follow practical steps to protect your account and respond to unexpected access.
Last updated August 25, 2026
A few account practices can reduce the risk of someone gaining access to your organisation's contracts.
Protect your sign-in
- Use a password that you do not use for another service.
- Keep sign-in magic links and authenticator codes private.
- Enable multi-factor authentication for an additional sign-in step.
- Check the address of the page before entering your password or authenticator code.
- Do not share a Scriboflow account. Invite each teammate with their own email address instead.
If you set a Scriboflow password, it must contain at least eight characters, including at least one letter and one number.
If you suspect unexpected access
- Open Settings and select Profile.
- Change your password.
- Enable multi-factor authentication if it is not already enabled.
- Open Settings > Organisation and review members and pending invitations.
- Remove unexpected members or revoke unexpected invitations if your role allows it.
- Contact Scriboflow and describe what you noticed and when.
Never include your password, magic link, authenticator setup key or six-digit authenticator code in a support message.