Active sessions

Last updated 25 August 2026

Every sign-in creates a session. Reviewing them is how you spot access you did not authorise.

What the session list shows

Device and browser, approximate location from IP, first sign-in time, and last activity. The current session is marked.

Revoking

Revoke a single session to sign that device out immediately, or revoke all other sessions in one action. Revocation takes effect on the next request from that device.

Session lifetime

Sessions persist across refreshes and browser restarts and expire after a period of inactivity. Changing your password or disabling two-factor authentication terminates every other session automatically.

If you see something unfamiliar

1. Revoke all other sessions.

2. Change your password.

3. Enable two-factor authentication if it is not already on.

4. Review your bank connections and remove any you do not recognise.

5. Contact support so we can check the account's audit trail.

Location accuracy

Locations are derived from IP address and are approximate. A VPN, mobile network, or corporate proxy commonly reports a different city or country — an unexpected location alone is not proof of compromise.

// STILL NEED A HAND?

We reply to every message, usually within a business day.

Contact support