Two-factor authentication
Backup codes and sessions
Two-factor authentication
Under Settings → Security you can register a second factor: an authenticator app (1Password, Authy, Google Authenticator, or similar) using a scanned or pasted setup key, or an SMS number. It's strongly recommended for any account that collects rent or holds tenant data.
One honest caveat: step-up enforcement is still rolling out, so a registered factor isn't yet demanded at every sign-in. Until it is, treat a strong, unique password as your primary protection and keep 2FA registered as the second layer.
Go to Settings → Security.
Choose "Add authenticator app" (or enter a phone number for SMS).
Scan the QR code or paste the setup key into your authenticator app.
Enter the 6-digit code it generates to verify and enable.
Backup codes and sessions
Once you have a verified factor, generate single-use backup codes and store them somewhere safe (a password manager) — they're your way back in if you lose your authenticator. You can download or copy them, and regenerating invalidates any old unused codes.
The Security screen also lets you sign out of every device at once (useful if a device is lost or stolen) and shows a login history of recent activity with browser, OS, and IP. If anything looks unfamiliar, change your password and confirm 2FA is on.
Under Settings → Account, "Your data" lets you download a copy of everything Aptoria holds about you — profile, leases, payments, messages, work orders, and more — as a personal-data export (GDPR Article 20).
Every agent action and every policy change is recorded in a tamper-evident, hash-chained audit log, viewable as one chronological timeline you can filter by actor and date. From it you can export a CSV for compliance reviews (on the web app) and produce a Decision Integrity Certificate that attests the chain hasn't been altered. Separately, the agent activity feed shows a plain-language "why" for each autonomous decision, with undo where the action was reversible.