Help · Getting connected
Two-factor authentication and account security
Two-factor sign-in is required. How it works, how sessions are handled, and how your data is protected.
Updated
Gladpaid can post entries into your books, so every account is protected by two-factor authentication. It is required, not optional, for every member of every business and firm.
Setting up two-factor
- 01
Open an authenticator app
Any time-based one-time password app works, such as the one built into your password manager.
- 02
Scan the code
During sign-up, scan the QR code Gladpaid shows, or type the setup key.
- 03
Enter a code to confirm
Type the six-digit code the app shows.
- 04
Save your backup codes
Keep them somewhere safe. Each works once if you lose your phone.
Signing in with Xero, Intuit or Google still asks for your Gladpaid second factor.
Sessions
Settings → Profile → Sessions lists where you are signed in. Sign out of any session you do not recognise, then change your password. Changing your password or two-factor settings signs out your other sessions.
How your data is protected
| Control | What it means |
|---|---|
| Encryption at rest | Ledger access tokens are encrypted with a key held in Google Cloud Key Management Service. The key never leaves it. |
| Row-level security | The database itself separates each business's data on every query, so a query that forgets its scope returns nothing. |
| Audit chain | Every action is appended to a log where each entry carries the hash of the one before it, so a changed history is detectable. |
| Key guard | Recovery phrases and private keys are refused everywhere. See Why we never ask for keys. |
The full list of controls and the services that process data are on Security & custody and Subprocessors.
Related
- Why we never ask for keys or recovery phrasesGladpaid refuses private keys and recovery phrases everywhere, never logs them, and never needs them.
- Team members and rolesInvite unlimited members on every direct plan. What Owners, Bookkeepers, Reviewers and Viewers can do, and how firm roles work.
- Exporting and deleting your dataExport everything as XLSX or JSON, disconnect your ledger, and delete a business. What is kept, for how long, and why.
Did this not answer it? Write to support@gladpaid.com with the business name and the item. Please never include a recovery phrase or private key; we will never ask for one.