Security
How people prove who they are, and what happens when something looks wrong.

Sign-in method, second factor, session length and device history. A financial system is only as safe as the weakest sign-in on it.
Passkeys are the strongest option available and they are also the easiest, which is an unusual combination worth taking.
Where everything sits






How to work this page
They cannot be phished, they cannot be reused, and they are faster than a password. There is no argument for anything weaker.
Especially anyone who can move money. A password alone on a payment-capable account is not defensible.
Shorter sessions on shared machines. Longer is fine on a device only one person uses.
Every device that has signed in, when, and from where. An unfamiliar one is worth acting on immediately.
On a phone

Every figure from the desktop appears here, stacked rather than reduced. Tables scroll inside themselves so the page never moves sideways, and figures keep their separators and their alignment at every width.
Questions people actually ask
Recovery through a second registered device or an administrator. Registering two devices at enrolment avoids the whole problem.
Yes, individually or all at once. Revoking all sessions is the right first move if you suspect a compromise.