How we protect your account sign-in
Passwordless by default, encrypted sessions, and SSO for teams that need it.
Written By Alex
Last updated About 2 hours ago
Most account compromises start with a password, so SignSolid does not use one.
How you sign in
- Google or LinkedIn. Authentication happens with your provider, and their protections apply.
- A one-time magic link. Single use and sent to your inbox, so only someone with access to that inbox can sign in.
- A passkey. Bound to your device and your biometrics or device PIN. Nothing to phish and nothing to reuse.
- SAML single sign-on. For organisations that want sign-in governed by their own identity provider.
What protects your session
- Your session lives in a secure, encrypted cookie.
- Sign-up is limited to valid, non-disposable email addresses.
- Once you are in, what you can do is set by your role in that workspace.
The result
With no password to steal, guess, or reuse, the most common route into an account is closed, and encrypted sessions plus role based access limit what any single compromise could reach.