Security
Password
Change your password with current, new, and confirm fields. A live checklist shows every rule at once: at least 8 characters, upper and lower case, a number, and that the new password is different from your current one; confirm must match. The update control stays disabled until every rule passes. Errors and success are shown on the page and as toasts.
The page shows when your password was last changed (relative wording), or that it has never been changed when there is no record.
Two-factor authentication (2FA)
Two-factor authentication uses an authenticator app (TOTP)—the UI mentions apps such as Google Authenticator and Authy as examples. You see whether 2FA is enabled or disabled.
Set up opens a guided flow (QR code and a verification code). With 2FA on, you get recovery codes and can open View to see them. Disable 2FA is available when you need to turn it off; store recovery codes somewhere safe outside the product.
Active session
For security reasons, only two concurrent sessions per user are allowed; opening a third signs out the oldest. This section summarizes your current sign-in so you can verify it matches the device and browser you expect.
You see the device type (for example desktop, phone, or tablet), a readable name, an Active label, operating system, browser, best-effort location (or unknown), and last active.