> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinzero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account security

> Password, passkeys, two-factor authentication, backup codes, and sessions.

# Account security

Open **Profile** → security section (Sign-in & security).

## Email verification

Your **Verified** badge on Profile confirms we reached your inbox. If it shows **Unverified**, use **Resend link** on Profile after you sign in — sign-in itself is blocked until your email is verified (security requirement for hospital data).

## Password

Change your password periodically. Use a unique password for ClinZero.

## Passkeys

Register a passkey (device or security key) for faster, phishing-resistant sign-in. You can remove passkeys you no longer use.

## Authenticator app (TOTP)

1. Choose **Enable** two-factor authentication.
2. Scan the QR code with an authenticator app.
3. Confirm with a one-time code.
4. Save **backup codes** somewhere safe (not in the patient chart).

Backup codes are single-use. Regenerate them from Profile if you lose the list — old codes stop working.

## Workspace policy

If your workspace **requires 2FA**, you will be prompted until it is enabled. Policy details appear on Profile when set by an admin under [Workspace settings](/admin/workspace-settings).

## Sessions and devices

Review signed-in sessions and sign out other devices if a laptop or phone is lost.

## Related

* [Sign in](/getting-started/sign-in)
* [Profile](/account/profile)
