Sign-in activity monitoring: quietly keeping accounts safe
When your product moves money, account security isn’t a feature — it’s the floor. This week we added another layer: sign-in activity monitoring across inflow.
What we record
Each time someone signs in (or their session refreshes), we record:
- when it happened,
- what device was used (the browser’s user agent), and
- the approximate location — city-level, derived from the network address.
That history gives us the raw material for real security questions: has this account suddenly signed in from another continent? Are many accounts sharing one network address? Is a sign-in pattern consistent with the real person, or with someone who found their email link?
What we deliberately don’t do
Location is approximate by design — it tells us a sign-in came from an unexpected country, not where anyone lives. Sign-in records live alongside our existing fraud monitoring and are visible to our security tooling, not to other users. And as always, sign-in itself stays passwordless: secure email links, no passwords to leak or reuse.
What’s coming
We’re building a view of your own recent sign-in activity into the account app, so you can check for yourself that every sign-in was really you — and flag anything that wasn’t.
Security questions or something odd on your account? Contact us right away.