Skip to Content
ProSettingsSecurity

Security

The Security page handles your account credentials. Today you can change your password here. Two-factor authentication and active-session management are on the roadmap.

To open it, go to Settings → Security in the sidebar.

Changing your password

The page has a single form:

FieldRequiredNotes
Current PasswordYesConfirms it’s really you
New PasswordYesMust meet the password rules below
Confirm New PasswordYesMust match the new password

Password rules

RuleWhy
At least 8 charactersHardens against guessing
At least one letterMixes character types
At least one numberMixes character types
Different from your current passwordAvoids accidental no-op changes

Examples that pass:

  • Tax2026!
  • Compliance123
  • BlueOcean42

Examples that fail:

  • password — no number
  • 12345678 — no letter
  • tax — too short

The form checks the rules as you type, and Assure Pro double-checks when you save.

What happens when you save

  1. Assure Pro stores your new password securely.
  2. You stay signed in on this device.
  3. Other devices or browsers where you were signed in get signed out — they’ll need to sign in again.
  4. A green confirmation appears: “Password changed successfully.”

Assure Pro doesn’t send you an email about the change today. Email confirmation on password change is on the roadmap.

[Screenshot: Change password form]

Resetting a forgotten password

If you can’t remember your password:

  1. Sign out (or close the browser).
  2. On the sign-in page, click Forgot password.
  3. Enter your email.
  4. Check your inbox for a reset link.
  5. Click it and set a new password.

The reset link works once and expires after 30 minutes.

Account lockout

After 10 failed sign-in attempts in 15 minutes, your account locks for 30 minutes. During lockout:

  • Sign-in attempts show “Account temporarily locked”.
  • The Forgot password flow still works — using it clears the lockout.

The lockout protects against brute-force attempts without permanently blocking you out.

Signing out

The sign-out button lives in the sidebar, at the bottom of the user menu — not on this page. Clicking it:

  1. Ends your login session.
  2. Sends you back to the sign-in page.

Signing out on this device doesn’t sign you out on others — they keep their own session until it expires. Managing other sessions is on the roadmap.

What’s missing today

FeatureStatus
Two-factor authenticationRoadmap — authenticator apps and security keys planned
Active sessions viewRoadmap — “see where I’m signed in”
Sign out a specific deviceRoadmap
Password strength meterRoadmap
Passkeys (passwordless)Roadmap
Single sign-on for enterpriseRoadmap
Forced password rotationNot planned — modern guidance is “rotate on breach”, not on a schedule

If your firm needs two-factor today, use a password manager (1Password, Bitwarden) with strong unique passwords. Two-factor is a known gap on our side.

What this page won’t do

SettingWhere to do it
Change your email addressNot yet in the UI — on the roadmap
Change your name or phoneTop-right user menu → Profile
Reset another teammate’s passwordNot possible — only the user themselves can reset their password. Direct them to Forgot password on the sign-in page.
Manage shared firm loginsFirm credentials

Audit log

Password changes show up in the firm activity log:

May 22, 4:12 PM Jane Chen changed her password.

Firm owners can review this through the activity timeline.

Permissions

Anyone can change their own password. No permission gate.

There’s no admin “reset another user’s password” function today. Admins can revoke a user’s account (roadmap) or rely on the user’s own Forgot password flow.

Next

Last updated on