Help center
Account and security
Profile, password and sessions, two-factor, Sign in with Apple, deleting your account, the support inbox and Ask NHM, privacy and retention, compliance records.
Updated · 7 articles
One account serves the web dashboard, the iOS app, the API and the MCP server. This category covers the account itself: how you get in, how you stay in, how you leave, how you reach a person, and what DomainGuard keeps about you.
Articles
- Profile, password and sessions - changing details, password rules and lockout, refresh tokens, the QR handoff between web and phone, and sign out.
- Two-factor authentication - TOTP set up on the web, eight recovery codes, and how the app handles the code.
- Sign in with Apple - native and web, relay addresses, linking Apple to an email account.
- Deleting your account - the request and confirm flow, what is erased, and the Apple subscription you must cancel yourself.
- Support inbox and Ask NHM - Ask for help on every plan, Ask NHM on a finding (Enterprise), thread statuses, and requesting website help.
- Privacy and data retention - what is stored, what is hashed, what is pruned and when, and what DomainGuard never touches.
- Compliance records - PCI-DSS, HIPAA and CMMC control checklists with statuses and notes, plus incident and WISP records.
The rules the account follows
- One account, every surface. The web dashboard, the iOS app, API keys and the MCP server all read the same account and the same plan; a change on one is visible on the others on the next refresh.
- You stay signed in until you sign out. The app never clears a session on a network error, a failed refresh or a Keychain read failure; it shows a banner. The web keeps a session cookie.
- Every security action is logged. Sign-ins and failed attempts, key creation and revocation, two-factor changes, impersonation by support, and account deletion are in the audit log, kept for a year.
- The notification email should be off the domains you watch. The point of the product is that the renewal notice does not land in a mailbox on the expiring domain.
Common questions
Can two people share an account? The account is one identity. For a team, use one account with one set of credentials in a password manager, or separate accounts per client; there is no per-user role model today. Support staff can open your account in a logged impersonation session when you ask for help.
Where is the audit log? It is not exposed to customers as a page yet; support can read it when you ask.
In reading order
Articles in Account and security
- Profile, password and sessionsUpdate your details; change or reset a password; the 30-minute lockout; 90-day refresh tokens; the QR handoff from the web to the phone; and signing out.Updated
- Two-factor authenticationTime-based one-time codes from an authenticator app, set up on the web dashboard, with eight recovery codes; how the iOS app and the API behave once it is on.Updated
- Sign in with AppleSign in with Apple on the iOS app and on the website, what happens with a hidden relay email, linking Apple to an existing email account, and revocation.Updated
- Deleting your accountThe request-and-confirm flow on the web, the type-DELETE flow in the app, what is erased, and why an Apple subscription has to be cancelled separately.Updated
- Support inbox and Ask NHMAsk for help on every plan; Ask NHM on a finding opens a thread with a person on Enterprise; thread statuses, archiving, and website-help requests.Updated
- Privacy and data retentionWhat DomainGuard stores, what it hashes or encrypts, how long operational records are kept, what it never reads or changes, and the ads on Free.Updated
- Compliance recordsAccount-level checklists for PCI-DSS, HIPAA and CMMC with a status and notes per control, plus incident and WISP records, as evidence for auditors and insurers.Updated
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
