Account security combines credential protection, MFA, trusted devices, risk checks, and revocation controls.
Root MFA
Root accounts must keep MFA enabled. Root cannot disable MFA into an unenrolled state; the supported path is authenticator replacement or a short-lived, audited enrollment recovery.
Trusted devices
A verified Root device may be trusted for no more than 30 days. InferGate stores a hash of a random device credential and binds it to the account, browser credential, and session version. A complete IP address is not used as a permanent binding.
When MFA is required again
- A new browser or device.
- Cleared cookies or expired trust.
- Password change, MFA reset, or sign-out from all devices.
- Managing trusted devices.
- Anomalous or high-risk login activity.
API Key responsibility
Users are responsible for protecting API Keys and account credentials. Disable a Token and contact support immediately after suspected compromise.
Security reports and appeals
Send reports to support@useinfergate.com without including secrets. Account restrictions remain enforceable while a review is pending.