Your password is checked first. If the browser you are using is not one we have seen before for your account, we then send a six-digit code to the email address on the account and ask you for it. A stolen password on its own therefore does not get anyone in.
Once a device has been verified it is remembered for 90 days, so you are not asked again on the same browser. We recognise the browser itself, not your IP address — a phone that moves between networks stays recognised.
If the code does not arrive
- Check the spam or junk folder. The code is sent from a no-reply address, and some filters treat it as bulk mail.
- Use “Send a new code”. A code is only valid for ten minutes, and asking for another replaces the previous one.
- Check the address is right by looking at your profile in the portal. Notices and codes go to the address on the account, which only you can change.
- If it still does not arrive, contact your account manager. They can see whether it was sent and whether it was delivered.
Adding an authenticator app (optional)
An authenticator app is available as a second check and is not required. If you add one, it is asked for whenever you sign in, in addition to the emailed code on a new device.
- 1Open Security in your client portal.
- 2Start the setup and add the account to your authenticator app using the displayed key.
- 3Enter the six-digit code your app generates to confirm.
If you lose your authenticator
Contact your account manager. For your protection, turning an authenticator app off is done by our team after confirming who you are — there is no self-service bypass, because a self-service bypass would be the weakest link in the whole scheme.
Devices you have trusted
The Security page lists every browser you have verified, with when it was first added and when it was last used. You can remove any of them, and the next sign-in from that browser will ask for a code again. Changing your password removes all of them, which is the behaviour you want if you are changing it because you are worried about access.
