Steerd Help

Your security

Changing your password, changing your email, and what each one does to your other sessions.

Changing your password

Changing your password signs out your other sessions.

That is the important sentence, and it is exactly the behavior you want: if you are changing your password because you think somebody else has it, signing every other session out is the point.

It also means changing your password on your laptop signs you out on your phone. That is not a bug.

The minimum length is stated on the form. Steerd does not impose character-class rules, because length is what actually matters and rules mostly produce Passwort1!.

Two passwords are refused outright, and both refusals are worth understanding:

  • A password known to have been breached. Steerd checks against a bundled list of passwords that have appeared in public breaches. The check runs locally, so your password is never sent anywhere to be looked up.
  • A password built out of your own name or email address. These are the first guesses anybody makes, and they survive every length rule.

Both apply when you register and when you change your password later.

Too many sign-in attempts

Repeated failures on an account, or from one address, start being refused with "Too many sign-in attempts". There are several limits stacked: a short burst limit measured in minutes, and a much larger daily one. The message tells you how long to wait, and the wait clears on its own.

It counts failures, not sign-ins, so nobody can lock you out by using your account, and completing a password reset clears it. There is deliberately no locked state that only support can undo.

The security log records failed sign-ins, throttling, and the successful sign-in that follows failures. That record survives account deletion, which the privacy notice states, because a log somebody can erase by deleting the account is not a security log.

Two-factor authentication

Turn it on under Security. Steerd uses an authenticator app that shows a 6-digit code, the same kind you already use elsewhere. There is deliberately no email code option: your email is also how you recover the account, so a code sent there is not a second factor.

When you turn it on you get backup codes. Save them somewhere that is not the phone holding the authenticator. Each one works once, and they are the difference between a lost phone costing you a minute and costing you three days.

If you lose your authenticator

In this order:

  1. Use a backup code on the sign-in screen. This works immediately.
  2. Ask a colleague who is an admin or the owner of your team to turn it off for you, under Team. This also works immediately, and you get an email telling you it happened.
  3. Ask Steerd, from the Lost your authenticator? link on the sign-in screen. This one takes 72 hours.

The wait is not us being slow. During those 72 hours the account keeps two-factor authentication on, and anyone who still holds the authenticator can stop the request from the email we send. If somebody who knew your password asked for this, that email and that link are what save the account. So keep the email either way: you need it to finish, and you need it to stop.

Two people cannot be helped by step 2: the owner of a team, and anyone who owns or helps run another team. Turning off their second factor would weaken an account with authority somewhere the person clicking the button has none, so those accounts always use the 72 hour route.

Changing your email

Also here rather than on your profile, because it changes what you sign in with.

Steerd confirms the change with your current address before it takes effect. So an attacker with a live session still cannot quietly move your account to an address they control without the old mailbox noticing.

What to do if you think an account is compromised

  1. Change your password, which ends the other sessions.
  2. Revoke API keys you do not recognize.
  3. Revoke contacts sync passwords for devices you no longer have.
  4. Check Connected apps under Integrations and revoke anything unfamiliar.
  5. If you are an admin, read the audit log.

Those four credential types are independent. A password change alone does not revoke an API key, and that is the step people forget.

On this page