Security is important to us here at ContractSafe. On all of our plans, you can enable Two Factor Authentication for your account.
For Admins - Enable two factor authentication on the whole account.
For all users - Set up two factor authentication on your account for the first time.
For Admins - Enable two factor authentication on the whole account.
Go to the Settings>Security and Integrations. Then, just click on the toggle button for Two Factor Authentication:A "Setting Enabled" banner should then appear on the lower left of the screen indicating that 2FA has been enabled.
For all users - Set up two factor authentication on your account for the first time.
Note: A smartphone with an active internet connection is required to continue.
Using an Authenticator App over Text message authentication (OTP) is recommended.
Please reach out to your IT/Security Administrator for advice on what Authenticator app to use. We recommend using Google Authenticator if you are already on the Google ecosystem, and Microsoft Authenticator if your company uses Microsoft.
On your browser, go to app.contractsafe.com
Log in using your login credentials. You will then be prompted to set up two factor authentication: Select any of the two options, and click "Submit". In this example, the selected option is "Authenticator App"
A new screen will appear with a QR code visible.
Please open your smartphone and authenticator app. Select the option to add an account by scanning a QR Code.
Aim your mobile camera to the QR code, and the account should be automatically added with the label "app.contractsafe.com" or similar. A dynamic code is generated on the app and it changes every few seconds. (The code on the screenshot below is partially covered for security purposes.
Type the code generated to the ContractSafe website, click submit, and finally, select to trust the device.
Note: Only choose Yes (trust this device) if you are using your own computer. Clicking "Not now" or "Never" will still allow you to log in, but will prompt you to type in a 2FA code again later on.
Similar steps can be taken to set up 2FA using a mobile number. With the only difference being the source of the code being a text message versus an app. ContractSafe recommends using an Authenticator App instead, as text message authentication (OTP) is vulnerable to various attacks, including SIM-swapping and phishing, where attackers can intercept authentication codes and gain unauthorized access to accounts.
See Also: How do I change my Dual-Factor Authentication (DFA) method?
Please do not hesitate to reach out to support@contractsafe.com for further inquiries.