Account security

The ways you can sign in to SIMCOAI, and which to choose for an account that can spend money and read customer conversations.

Where

Where signing in happens

Choosing to sign in takes you to auth.simcoai.co.uk. That is SIMCOAI’s own sign-in address, powered by our identity provider and branded for SIMCOAI. It is the same account throughout — there is nothing separate to register.

It is a separate address on purpose. Passwords, one-time codes and sign-in links are handled entirely by that service, so they never pass through the dashboard or through your workspace. When you reset or change a password, you set the new one there and it is not sent to the dashboard.

Your business data — your profile, customers, bookings, calls and conversation history — stays in SIMCOAI’s own database and is linked to your account by an identifier, not by your password.

  • Signing in: you are taken to auth.simcoai.co.uk and returned to your dashboard once you are in.
  • Changing your password: Security in the dashboard emails you a secure link. The form does not ask for the new password, because your workspace is not where it is set.
  • Signing in with Google: there is no separate SIMCOAI password on your account at all, and the dashboard tells you so rather than offering to change one.
  • Where your password lives: only on the sign-in service. SIMCOAI holds no password record for your account, in any form.
  • Where you change things: sign-in methods are added and removed on the sign-in page itself, not inside the dashboard, so a change applies everywhere rather than to one browser.
Methods

Sign-in options

MethodStrengthNotes
PasskeyStrongestAvailable now. Phishing-resistant, nothing to type. Choose Continue with a passkey when you sign in. Bound to your device unless your platform syncs them.
Authenticator appStrongTime-based codes. Supported by the sign-in service; ask us to switch it on for your account.
Security keyStrongA physical key such as a YubiKey. Supported by the sign-in service; ask us to switch it on.
Google sign-inGoodSecurity follows your Google account, including its own MFA.
Magic linkConvenientSingle-use and short-lived. Mail scanners can consume links before you do.
Recommended

What we suggest

  • Add a passkey on the device you use most, and keep a second method as backup. This is the strongest option available today and takes one tap at sign-in.
  • Keep your password as the backup if you add a passkey, so losing the device does not lock you out.
  • Do not share one login across a team - individual accounts mean the audit trail is meaningful.
  • Remove access when someone leaves. This is the most commonly skipped step.
Never

Things SIMCOAI will never do

Careful. Nobody at SIMCOAI will ever ask you for your password, an MFA code, or to approve a passkey prompt you did not start. Any such request is an attack, whoever it appears to come from. Report it via report a bug.
Trouble

If you cannot get in

See login problems. Support cannot bypass MFA for you - that is the point of it.