Two-step verification

Required for counsel, platform admin, and sensitive actions. Turn it on in Settings. Some call this multi-factor authentication (MFA) or 2FA.

Ask AI about this article ChatGPTClaudePerplexity
Settings: security
The Backup codes block in Security settings showing 10 of 10 codes remaining, the date the set was generated, and a Replace backup codes button
Backup codes under Settings, Security: how many of the ten remain and when the set was generated. The codes themselves are shown once, when issued; Replace backup codes asks for your password and retires the old set.

Who must turn it on

Counsel and platform admins must use two-step verification at every sign-in. A new company workspace sets it up once at the end of checkout; company roles are never blocked at sign-in afterward.

Some actions need it whatever the role: requesting company verification, storing or testing your EDGAR codes, and downloading the company records. Company verification is granted only once every company admin has it on.

A company admin can require it for everyone: Require two-step verification, under Sign-in security on Settings › People › Team. Each person without it is then asked to set it up before they open the company; the admin needs it on their own account first. Each person's row reads Two-step on or Two-step off.

Set it up

Add an authenticator app or a mobile number from Settings › Security.

  1. Scan the QR code, or verify the mobile number, and enter the six-digit code.
  2. Save the ten backup codes shown next; they are shown only once.
Note

If you enrolled at the sign-in gate, generate your backup codes under Settings › Security after your next sign-in.

Codes at sign-in

A texted code may take a moment to arrive and expires after a few minutes. Do not share it; TakePublic never calls or texts to ask for a code.

Backup codes

Backup codes are the ten single-use codes you saved when you set up two-step verification; they stand in for your authenticator app or phone, and each signs you in once, with your password. Keep them in your password manager; TakePublic stores only a fingerprint of each code and cannot show them again.

Replace backup codes under Settings › Security issues a new set after you enter your password, and the old codes stop working at once. Every use of a backup code emails you, so you know if someone else used one.

Lost device

Sign in with a backup code, then replace the lost method.

  1. Sign in with your email and password. Backup codes need a password sign-in; if you only sign in with Google, add a password under Settings › Account first.
  2. On the two-step screen, choose Lost your authenticator or phone? Use a backup code and enter a saved code.
  3. Under Settings › Security, add a new method and generate a fresh set of backup codes.
Note

Support never asks for a code or a password, and cannot see your backup codes.

More detail

If you have no backup codes either, ask a company admin on your team to open a support request from the Help widget. Support verifies your identity out of band (a call to a number the company admin confirms, and for a counsel seat the company admin's written confirmation), then resets two-step verification on your account.

The reset removes your authenticator and text-message methods, clears your backup codes and trusted devices, ends every signed-in session, and emails you saying so. It is recorded in your company's audit log with the identity check support performed. At your next sign-in you set up two-step verification again before you can continue, whatever your role.

Was this helpful?

Up next

How TakePublic protects your data

Encryption, need-to-know access, the inside-information policy, and no training on your content.

Support

Still need help?

Sign in and open the Help widget in the lower right corner to message the team. Replies land in the app and by email.

TakePublic is a technology platform, not a law firm, broker-dealer, or auditor. Forms 3, 4 and 5 prepared in TakePublic file only after the reviewer the company designates, such as its securities counsel, signs off; any other filing prepared in TakePublic files only after a licensed securities attorney signs off.