inflow
Security July 12, 2026

Sign-in activity monitoring: quietly keeping accounts safe

When your product moves money, account security isn’t a feature — it’s the floor. This week we added another layer: sign-in activity monitoring across inflow.

What we record

Each time someone signs in (or their session refreshes), we record:

  • when it happened,
  • what device was used (the browser’s user agent), and
  • the approximate location — city-level, derived from the network address.

That history gives us the raw material for real security questions: has this account suddenly signed in from another continent? Are many accounts sharing one network address? Is a sign-in pattern consistent with the real person, or with someone who found their email link?

What we deliberately don’t do

Location is approximate by design — it tells us a sign-in came from an unexpected country, not where anyone lives. Sign-in records live alongside our existing fraud monitoring and are visible to our security tooling, not to other users. And as always, sign-in itself stays passwordless: secure email links, no passwords to leak or reuse.

What’s coming

We’re building a view of your own recent sign-in activity into the account app, so you can check for yourself that every sign-in was really you — and flag anything that wasn’t.

Security questions or something odd on your account? Contact us right away.