Skip to Content
Security & trustAccount protection

Account protection

Your account is protected from the moment you create it. You sign in with your email and a password, every new account has to confirm its email before it goes live, your sign-in stays active only for a limited time, and you can reset your password or sign out yourself at any time. None of it depends on you remembering to turn something on.

What it is

This page explains, in plain terms, how TrueTone protects the front door to your account. It is the trust view of signing in: not the step-by-step how-to, but the principles a careful person or a security reviewer wants confirmed before trusting the system with their voice, their content, and their clients’ information.

Four things work together to keep your account yours: how you prove it is you, why a new account has to confirm its email, how long a sign-in lasts, and how you get back in or step away safely.

Who it is for

  • Loan officers who want to know their account cannot be claimed or quietly used by someone else.
  • Org admins describing account protection to the loan officers on their company account.
  • Security reviewers evaluating TrueTone who need the principles, stated honestly, including what is live today and what is still on the way.
  • Sales, marketing, and support teammates who need to describe sign-in accurately without overselling it.

How your account stays protected

You prove it is you

You sign in with your email address and a password you choose. That pairing is what identifies you, so an account is only as reachable as the person who holds both. A show-and-hide control lets you confirm your password before you submit it, so a typo does not lock you out.

A new account confirms its email

When you create an account, TrueTone sends a verification link to your inbox and holds the account until you click it. This confirms the address is really yours, so an email you do not control cannot be turned into a working account. Confirming your email is required, not optional. If you try to sign in before confirming, TrueTone sends you back to finish that step rather than letting you in.

Your session is time-limited

Once you are in, you stay signed in on that device for about a week, and that window quietly refreshes as you keep using TrueTone. It does not last forever. When the window lapses, you sign in again. This keeps a forgotten open tab or a borrowed laptop from staying signed in indefinitely.

You can step away or reset on your own

You never have to contact anyone to manage your own access. Sign out whenever you want and your session on that device ends. Forget your password and you can request a reset link from the sign-in screen and set a new one yourself. Both are self-serve, by design.

Confirming your email

Email verification is the quiet workhorse of account protection. Because every new account must confirm its address before it goes live, nobody can stand up a working TrueTone account using an email they do not actually control. Clicking the verification link both confirms the address and signs you in, so you land in your account rather than bouncing back to a login screen. Verification links do not last forever, and if yours has gone stale you can request a fresh one.

💡

The step-by-step version of creating an account, confirming your email, and signing back in lives on Signing up and signing in. This page focuses on why those steps protect you rather than how to click through them.

Resetting a forgotten password

If you forget your password, you get back in on your own. You request a reset link from the sign-in screen, and TrueTone shows the same confirmation whether or not an account exists for that address, so the screen never reveals who does or does not have an account. If an account does exist, a reset link arrives in your inbox, you set a new password, and you are back in. Reset links expire, so a stale one can simply be requested again.

Signing out

Signing out ends your session on the device you are using and returns you to a clean sign-in screen. It is a deliberate, immediate action you control. Signing out in one place does not disturb your access on your other devices, so ending a session on a shared computer does not lock you out of your own.

A second kind of credential: API keys

Signing in with your email and password is not the only way your account can be exercised. From the API Keys page in your account you can create keys for the TrueTone API, and you can connect an AI assistant through the TrueTone Connector, which uses your TrueTone sign-in and an approval screen rather than a key. Both are deliberate, self-serve grants, and both deserve the same care as a password.

  • A key is shown once. The secret appears when the key is created or rotated and never again, so it cannot be recovered later, only replaced.
  • You choose what it can do. Every key and every connection is limited to the Capability Groups you grant when you create or approve it. Nothing gets more than you chose.
  • You can end it yourself. Rotating a key retires the old secret after a short grace window, so nothing you run breaks mid-switch. Revoking a key stops it immediately, with no grace and no undo, which is exactly what a leaked secret needs.

Treat a key like a password: anyone holding it can do whatever its Capability Groups allow. If a key may have been exposed, revoke it and create a new one; your password and your signed-in sessions are unaffected. The full guide is API keys and AI connections.

What is live today, and what is on the way

⚠️

So nothing is oversold, here is the honest state of sign-in:

  • Email and password is the only way in today. It is live, and it is what you and everyone on your account use to sign in right now.
  • A one-time email sign-in link and Google sign-in are on the way. They are part of the foundation of the TrueTone System but are not yet offered as buttons on the sign-in screen. Until they are, use email and password, and reset your password from the sign-in screen if you forget it.

Good to know and limits

💡

A few things worth keeping in mind:

  • Your email is your identity. One email means one account, so use an address you check regularly and keep control of.
  • Verification and reset links expire. This is protection, not a bug. If a link no longer works, request a fresh one from the relevant screen and nothing is lost.
  • Keeping your own sign-in safe is the other half. TrueTone protects the front door; a strong, unique password protects the key. See Account security for practical tips.
  • This is a principles page. It describes what protects your account and how you would see it working, not the internal mechanics. If you need contractual or technical detail beyond this, ask your TrueTone contact.

Protecting your sign-in is one layer. Your organization’s data is walled off from every other organization’s and that separation is enforced and audited, spending is capped so nothing can run away, and any time a person acts on your account it is a deliberate, recorded choice. Those layers each have their own page below.

Last updated on