Securing your account with two-factor authentication
Overview. Two-factor authentication (2FA) adds a second step to signing in, so a stolen or guessed password is not enough on its own to reach your account. IdentityCheck supports app-based 2FA using an authenticator app on your phone. It is mandatory for all paid accounts, so every user on a paid plan sets it up, and any user on the free plan can turn it on too.
How do I turn on two-factor authentication?
Open your security settings and choose to enable two-factor authentication. IdentityCheck shows you a code that you scan with an authenticator app on your phone, such as the authenticator app you may already use for other services. The app then generates a fresh six-digit code every 30 seconds. Enter the current code once to confirm the setup, and 2FA is active on your account.
From then on, when you sign in you enter your password as usual and then the current six-digit code from your app. When you set 2FA up, IdentityCheck also gives you a backup code. Save it somewhere safe and separate from your phone. If you ever lose access to your device, that backup code is how you get back in.
Because it is app-based, this protection works even if your phone is offline, and it does not rely on receiving a text message. It is one of the simplest and most effective steps you can take to protect the client information in your account.
Is it mandatory?
Yes, on paid accounts. Two-factor authentication is mandatory for all paid plans, so every user has to set it up before they can use the app. This is part of StackGo's security policy for handling client identity and compliance data, and it is enforced by our third-party providers as well, so it is not something a firm switches off.
Any user who has not yet set it up is guided to do so the next time they sign in, before they can reach the rest of the app. New teammates you invite go through the same step as part of joining. The result is a consistent security baseline across your whole firm, rather than protection that depends on each person remembering to opt in.
Frequently asked
How do I turn on two-factor authentication? Open your security settings and enable two-factor authentication. You scan a code with an authenticator app on your phone, then enter the six-digit code it generates to confirm. Save the backup code you are given somewhere safe in case you ever lose access to your phone.
Can I require two-factor authentication for my whole team? Yes, on a paid plan. An account on a paid plan can make two-factor authentication mandatory, so every user must set it up before they can use the app. This gives you a consistent security baseline across the firm rather than relying on each person to opt in.
What if I lose my phone? Use the backup code you saved when you set up two-factor authentication to sign in, then re-enable it with your new device. If you have lost your phone and do not have the backup code, contact support and we can reset 2FA on your account. This is why it matters to store that backup code somewhere safe and separate from your phone when you first turn the feature on.
Can I disable two-factor authentication? Not on a paid account. 2FA is mandatory for all paid plans as part of StackGo's security policy, and it is enforced by our third-party providers too, so it cannot be turned off. This is deliberate: it keeps the client identity information in your account protected.
