Help center

Account and security

Profile, password and sessions, two-factor, Sign in with Apple, deleting your account, the support inbox and Ask NHM, privacy and retention, compliance records.

Updated · 7 articles

One account serves the web dashboard, the iOS app, the API and the MCP server. This category covers the account itself: how you get in, how you stay in, how you leave, how you reach a person, and what DomainGuard keeps about you.

Articles

  • Profile, password and sessions - changing details, password rules and lockout, refresh tokens, the QR handoff between web and phone, and sign out.
  • Two-factor authentication - TOTP set up on the web, eight recovery codes, and how the app handles the code.
  • Sign in with Apple - native and web, relay addresses, linking Apple to an email account.
  • Deleting your account - the request and confirm flow, what is erased, and the Apple subscription you must cancel yourself.
  • Support inbox and Ask NHM - Ask for help on every plan, Ask NHM on a finding (Enterprise), thread statuses, and requesting website help.
  • Privacy and data retention - what is stored, what is hashed, what is pruned and when, and what DomainGuard never touches.
  • Compliance records - PCI-DSS, HIPAA and CMMC control checklists with statuses and notes, plus incident and WISP records.

The rules the account follows

  • One account, every surface. The web dashboard, the iOS app, API keys and the MCP server all read the same account and the same plan; a change on one is visible on the others on the next refresh.
  • You stay signed in until you sign out. The app never clears a session on a network error, a failed refresh or a Keychain read failure; it shows a banner. The web keeps a session cookie.
  • Every security action is logged. Sign-ins and failed attempts, key creation and revocation, two-factor changes, impersonation by support, and account deletion are in the audit log, kept for a year.
  • The notification email should be off the domains you watch. The point of the product is that the renewal notice does not land in a mailbox on the expiring domain.

Common questions

Can two people share an account? The account is one identity. For a team, use one account with one set of credentials in a password manager, or separate accounts per client; there is no per-user role model today. Support staff can open your account in a logged impersonation session when you ask for help.

Where is the audit log? It is not exposed to customers as a page yet; support can read it when you ask.

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.