🔒 Account Security
Your NeoProtect account controls your protection, your billing and your support, so getting into it should be easy for you and hard for everyone else. This page covers passwords, two-factor authentication, passkeys and what to do when something goes wrong.
🔑 Beware of phishing
NeoProtect staff will never ask you for your password, a two-factor code, or a backup code — not in a ticket, not on Discord, not by email. Anyone who does is not us.
Forgot your password?
Send yourself a reset link and pick a new one.
Secure your account
Turn on two-factor authentication in a couple of minutes.
Locked out? 2FA lost?
Write to us from the email address of your account.
Everything below lives in your panel profile, under the Security tab.
Choosing a password
Use a long, unique password that you do not use anywhere else. Length beats complexity: a passphrase of four or five unrelated words is both easier to remember and harder to crack than P@ssw0rd!.
The single best habit is a password manager — it generates a different password for every site and means a breach somewhere else can never reach your NeoProtect account.
Reset a forgotten password
- Open the password reset page.
- Enter your account's email address and complete the captcha.
- Open the link in the email we send you and choose a new password.
⏳ The reset link expires after 1 hour
It is also single-use. If it has expired or you have already used it, just request a new one, old links stop working as soon as a newer one is issued.
Change your password
Go to Profile → Security, enter your current password and the new one twice.
If you signed in with a passkey or through single sign-on, your account may not have a password at all. In that case the form will reject your current password because there is nothing to compare against — use the reset flow instead to set your first password.
Two-factor authentication (2FA)
Two-factor authentication means that knowing your password is not enough to get in: a six-digit code from your phone is also required. It is the highest-value five minutes you can spend on your account.
To turn it on:
- Go to Profile → Security and start the 2FA setup.
- Scan the QR code with an authenticator app — Google Authenticator, Authy, 1Password, Bitwarden and any other TOTP app all work.
- Type the six-digit code the app shows to confirm the setup.
- Save the 10 backup codes we then give you. See backup codes.
2FA only switches on once you have entered a correct code, so a mis-scanned QR code can never lock you out of your own account.
To turn it off, go to Profile → Security and disable it. Your backup codes are deleted at the same time; enabling 2FA again issues a fresh set.
⏰ Codes are time-based
The code changes every 30 seconds and is derived from your device's clock. If your phone's clock is off by more than a few seconds, every code will be rejected — see troubleshooting.
Backup codes
When you enable 2FA we issue 10 backup codes. Each one is a long, randomly generated string and works exactly once. Used codes are not replaced, so the pool shrinks as you go through it. At login they go in the same box as the code from your authenticator app.
They exist for exactly one situation: your phone is lost, stolen, broken or wiped. Store them somewhere you can still reach without that phone — printed, or in a password manager you can open from another device.
You can view your codes any time under Profile → Security. If you are running low, disable 2FA and enable it again: that issues a fresh set of ten.
Lost your 2FA device
If you still have a backup code, use it in place of the six-digit code at login. Once you are back in, go to Profile → Security, disable 2FA and enable it again on your new device — this invalidates the old device and issues a new set of backup codes.
If you have no backup codes left, email support@neoprotect.net from the email address of the account. That is the only route back in.
📩 Write from the account's own email address
Sending your request from the address the account belongs to is how we establish that it is really yours. A request from any other address cannot be verified and will not be actioned, no matter what details it contains. Never include passwords, codes or backup codes in that email — we do not need them and will never ask for them.
Passkeys
A passkey signs you in with your device's fingerprint, face or PIN instead of a password, and cannot be phished or reused on a fake site.
Add one under Profile → Security. You will be asked to confirm your current password first. You can register several passkeys (laptop, phone, password manager, hardware key) and remove any of them from the same page.
Change your email address
Under Profile → Security, enter the new address. We send a verification link to the new address, and the change only takes effect once you click it. That link is valid for 30 minutes.
Keep this address current and accessible: it is how we verify you if you are ever locked out.
Sessions
Signing in creates a session that lasts for a few days, after which you sign in again. Signing out ends the session you are currently using; other devices stay signed in.
If you think someone else has access to your account, change your password, then remove any 2FA device or passkey you do not recognise, and contact support straight away.
Troubleshooting
| Symptom | What is usually happening |
|---|---|
| The reset email never arrived | Your address was never verified, so you were sent a verification email instead — look for that one. Otherwise check spam, and confirm you used the address the account is under. |
| The reset link says it is invalid | It expired (they last 1 hour), it was already used, or a newer link has since been requested. Request a fresh one. |
| My 2FA code is always wrong | Your device's clock has drifted. Turn on automatic date & time on your phone, then try the next code. A backup code works regardless of the clock. |
| Current password is rejected | The account may have no password (passkey or single sign-on). Use the reset flow to set one. |
| I cannot add a passkey | Adding a passkey requires your current password. Set one first. |
Still stuck? Open a ticket from the help desk, or see Support for the response times on your plan.
Security best practices
- Use a unique password, ideally from a password manager.
- Turn on 2FA — it is the difference between a leaked password being an inconvenience and being an outage.
- Store your backup codes offline, somewhere reachable without your phone.
- Protect the account's email address with its own strong password and 2FA. Anyone who controls that mailbox can reset your NeoProtect password.
- Keep that address reachable. An abandoned mailbox means no reset and no recovery.
- Give teammates their own access rather than sharing one login, so leavers can be removed individually.
- Never share a password, 2FA code or backup code, with anyone, including anyone claiming to be us.