Account
Your account is your identity on AISafe: the email you sign in with, your profile, your security settings, and any personal API keys. An account is separate from organizations. You sign up once, and your account persists across every organization you join.
Sign-in providers
You can authenticate three ways: passwordless email, GitHub OAuth, or Google OAuth. You need one to start, and you can link additional providers to the same account later. Your email is the primary identifier and receives important notifications, such as assessment completion summaries and security alerts.
AISafe supports TOTP-based two-factor authentication (2FA) with authenticator apps and backup codes for recovery.
Account vs organization
Your account is you. An organization (Organization) is the tenant where assessments, findings, projects, members, and billing live. You can belong to multiple organizations and switch between them from the organization switcher. Work in one organization stays invisible to members of another unless you invite them.
Your first account also gets a personal organization, so you can run assessments immediately.
Account settings
From your avatar menu you manage, independent of any organization:
- Profile — display name, avatar, and email address.
- Password — change it or set one if you signed up via OAuth.
- Two-factor authentication — enable or disable TOTP, view backup codes, and manage trusted devices.
- API keys — create and revoke personal keys used by the CLI and scripts.
- Notification preferences — choose which events trigger email or in-app notifications.
- Linked providers — connect or disconnect GitHub and Google.
Most account changes take effect at once. Email changes require confirmation at the new address first.
Next steps
- Create an account — the three sign-up flows
- Organization — the tenant your work belongs to
- Invite your team — add teammates and assign roles