Signing in and two-factor authentication
Last checked on
You sign in once at app.trustbird.com with your email address, your password and a code from your second factor. From there you open any workspace you belong to without signing in again.
Why this protects your organisation
Your workspace holds the security evidence, risks and supplier agreements of your organisation. A stolen or guessed password should never be enough to reach that. That is why every account needs a second factor on top of the password, and why a password change ends your sessions everywhere at once. ISO 27001 asks for controlled access to information (control 5.15) and for secure authentication (control 8.5). Trustbird applies both to your own account.
Steps
- Go to app.trustbird.com and enter your email address and password. Click Sign in.
- The first time, set up a second factor: an authenticator app, codes by email, or both. Keep the recovery codes of the app somewhere safe.
- On every later sign-in, enter the 6-digit code from the method you choose under How would you like to verify?
- Under Your workspaces, click Open next to the workspace you want to work in. With only one workspace you go there straight away.
- To change your password or manage your second factor, open Profile from the menu under your name.
Trustbird has one central sign in page at app.trustbird.com. After signing in you see Your workspaces: every workspace you are a member of, each with an Open button. Each workspace lives at its own address, such as yourcompany.trustbird.com. You can also sign in there directly; the page and the steps are the same.
Your second factor
Before you can do anything else, Trustbird asks you to set up two-factor authentication. There are two methods, and you may set up both:
- Authenticator app: an app on your phone that shows a new 6-digit code every 30 seconds. With it you receive recovery codes, for when the phone is gone. Store them outside Trustbird, for example in your password manager.
- Email verification codes: Trustbird emails you a 6-digit code each time you sign in.
You manage both methods on your Profile page, under Two-factor authentication (2FA). There you can also regenerate your recovery codes. If you turn off every method, Trustbird asks you to set one up again straight away.
Moving between workspaces
When you click Open, Trustbird signs you in on the address of that workspace for you. That hand-over works only once and only for a minute, and it is recorded in the audit log of the workspace. Advisers who work for several customers use this to move between them without signing in each time.
Your password and your sessions
On your Profile page you change your password by entering a New password, confirming it and giving your Current password. A new password signs you out on every other device and every workspace address. A session that stays unused for a while also ends by itself, after which you sign in again.
If it does not work
I lost the phone with my authenticator app
Click Use a recovery code instead and enter one of the recovery codes you saved when you set up the app. Each code works once. If you also set up codes by email, you can choose that method instead. Once you are in, set up the app again on your new phone and generate new recovery codes on your Profile page.
I cannot sign in and did not receive a confirmation email
Trustbird only lets you in once your email address is confirmed. Look for the confirmation email, including in your spam folder, and click the link in it. Use Forgot password? on the sign-in page if you are no longer sure of your password: you receive a one-time link by email.
I see Too many login attempts
After several wrong passwords for the same email address, Trustbird pauses new attempts for a while. Wait until the time shown has passed, or reset your password with Forgot password?
A workspace address shows a page that does not exist after I sign in
You are not a member of that workspace. Ask its owner to invite you, or go to app.trustbird.com to see the workspaces you do belong to.