Account and plan
Account, security and team
Everything that protects your account and organises your team: how to sign in, turn on two-factor authentication and passkeys, watch your sessions, and who can do what in a workspace.
Sign-in methods
| Method | Details |
|---|---|
| Email and password | Always available. Sign-in works only after the address is verified (link valid 24 hours). |
| Offered when Google sign-in is configured on the platform (OpenID Connect). | |
| GitHub | Offered when configured; only an email address verified at GitHub is accepted. |
| Passkey | WebAuthn with user verification (fingerprint, face, device PIN); enter your email first. |
Other options (Google One Tap, Facebook Login) exist but are off by default; they appear only when enabled. There is no magic-link sign-in.
Password rules
- 12 to 128 characters, with at least one lower-case letter, one upper-case letter, one digit and one symbol.
- It must not contain the local part of your email address (if that part is 4 characters or more).
- A reset link is valid 30 minutes; resetting the password closes all your sessions.
- An account created with Google or GitHub can add a password from the Security page.
Two-factor authentication (2FA)
- Open Account › Security (/account/security).
- Turn on two-factor authentication and scan the QR code with an authenticator app (6-digit TOTP codes).
- Confirm with a first code, then keep your 10 recovery codes offline: each works once.
- Once on, 2FA is also asked after a Google or GitHub sign-in.
- Recovery codes can be regenerated by providing an app code.
- Turning 2FA off requires a code (or a recovery code) and closes all sessions.
Sessions and security log
- A session lasts 30 days in an HttpOnly cookie.
- The Security page lists your active sessions, marks the current one, lets you close one, close all the others and rename a device.
- The log shows your last 25 security events: successful or failed sign-ins, lockout, 2FA enabled, recovery codes used, password changed, sign-in method removed…
- You can remove a sign-in method, except the last one: NeoRank refuses to leave you with no way to sign in.
Organisation, workspaces and roles
An organisation holds the subscription; it contains workspaces (sites, connectors, members). Workspace roles:
| Role | Can notably |
|---|---|
| Administrator | Manage the workspace, invite members, connect sources |
| Strategist | Connect sources, read the audit log |
| Analyst, Editor, Client viewer | View the workspace |
Billing is reserved for the organisation's owner, administrators and billing manager.
Inviting a member
- Account menu › Manage users › “Invite a colleague”: email, role, then “Invite”. Reserved for workspace administrators.
- The invitation is for one workspace and expires after 7 days; inviting the same address again replaces the previous invitation.
- The invitee accepts it by signing in with the invited address.
- The number of seats depends on the plan, and pending invitations count.
Your data
There is no self-service account deletion or full export button yet. The privacy policy describes your rights (access, rectification, erasure, portability) and the address to exercise them.