# Security Settings

To ensure the highest level of security for your earnings and personal data, the Affiliate Portal now includes a dedicated **Security Settings** tab. This guide outlines how to manage your password, enable Two-Factor Authentication (2FA), and understand the new security verification protocols for logging in and updating payment information.

#### 1. Accessing Security Settings

All security-related configurations have been moved from the generic Profile tab to a new, dedicated location.

1. Log in to your **Affiliate Account**.
2. Navigate to the **Settings** section.
3. Click on the **Security** **settings** tab.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FuXipQQcJgWJ6eqhPzHEk%2Fimage.png?alt=media&#x26;token=9a432523-2700-494f-be74-6ab34c90a2ff" alt=""><figcaption></figcaption></figure>

Here you will find two main sections:

* **Password Management**
* **Verification Methods**

#### 2. Password Management

We have enhanced the password change process to prevent unauthorized account takeovers.

To change your password:

* Go to **Security settings** tab > click **Change password**

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FUtslP97VqCmqZX3U0v1D%2Fimage.png?alt=media&#x26;token=c82f70fa-846a-4881-bb3a-bfd26bd1bf70" alt=""><figcaption></figcaption></figure>

* Enter your current password, new password, confirm password and click **Next**

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FSIFi0OUSFJX8dTOPKbKG%2Fimage.png?alt=media&#x26;token=2f02f45d-ce98-4149-ae31-f4e04fc07b85" alt=""><figcaption></figcaption></figure>

* A One-Time Password (OTP) will be sent to your registered email address. You must enter this code to finalize the password change.

**Note:** If you do not have access to your email, you will not be able to change your password. This ensures that even if someone guesses your password, they cannot lock you out of your account.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FODadEKJxnCHXHsYVtdCP%2Fimage.png?alt=media&#x26;token=70e66511-05ac-473b-9368-56ade331509a" alt=""><figcaption></figcaption></figure>

#### 3. Two-Factor Authentication (2FA)

Two-Factor Authentication adds an extra layer of security. It is a **secondary method** (optional but recommended) used to verify your identity when performing sensitive actions (update payment info/login).

#### Setting Up 2FA:

1. In the **Security** **settings** tab, locate the **Verification Methods** section.
2. Select **Enable 2FA**.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FuE1VGUmcxaViSGh22rZp%2Fimage.png?alt=media&#x26;token=9ce3bbed-031f-4617-b7fa-4abc6c8bd7d4" alt=""><figcaption></figcaption></figure>

3. Scan the QR code using an authenticator app (such as Google Authenticator or Authy) on your smartphone.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FHM1KHGUFSlJX9vy16Vtf%2Fimage.png?alt=media&#x26;token=9b4e8c94-d25f-48dc-8c76-dc73500d0f8c" alt=""><figcaption></figcaption></figure>

4. Enter the 6-digit code generated by the app and click **Next.**

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2Fcx5vQbrwEg6qqeheWA8l%2Fimage.png?alt=media&#x26;token=2d3157eb-d777-4b9d-8559-527081a149a9" alt=""><figcaption></figcaption></figure>

5. **Next**, An OTP will be sent to your registered email address. Enter this code to confirm and finalize 2FA activation.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FvwRMU8C8dWClSim3EAth%2Fimage.png?alt=media&#x26;token=fc94e9a8-b6c9-4aad-9f3e-644bc1c84bf5" alt=""><figcaption></figcaption></figure>

#### Customizing 2FA Scope:

Once enabled, you can choose when 2FA is required:

* **Login Account:** Require a 2FA code every time you sign in.
* **Update Payment Method:** Require a 2FA code only when changing payout details (highly recommended to prevent payment fraud).
* **Both:** For maximum security.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FBRlWbV85sE7e80PHJj91%2Fimage.png?alt=media&#x26;token=6c4e3112-8171-4826-bb8c-5c101be2eab2" alt=""><figcaption></figcaption></figure>

### 4. Using Verification Method

#### Updating Payment Information

When you attempt to change your payout email or bank details:

1. The system will ask for verification.
2. You will see two options (if 2FA is set up):
   * **Verify via 2FA App:** Enter the code from your phone.
   * **Verify via Email OTP:** Enter the code sent to your inbox.

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FRf2C8B8IrDnIS0RIhumJ%2Fimage.png?alt=media&#x26;token=a3e90e5e-2545-4c0a-9151-c830106db7d1" alt=""><figcaption></figcaption></figure>

#### Logging In

* **Standard Login (If 2FA is NOT Enabled):** Enter Email & Password only.
* **If 2FA is Enabled for Login:** You will be prompted to enter the code from your authenticator app or email OTP (if authenticator app is lost)

<figure><img src="https://2915776664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LnqRFg4of77qA6qOdUp%2Fuploads%2FZRFclrkHteIQS8hM3GVN%2Fimage.png?alt=media&#x26;token=15da58cb-23ab-4be9-8552-2509f70f32e7" alt=""><figcaption></figcaption></figure>

**Security Limits & Troubleshooting**

To prevent "brute force" attacks (hackers trying to guess your codes), the system implements strict limits.

* **Attempt Limit:** You have a maximum of **10 attempts** to enter the correct 2FA or Email OTP code per login session.
* **Temporary Lockout:** If you exceed 10 failed attempts, your account login/verification ability will be **blocked for 1 hour**.
