Account security in Calamus rests on three mechanisms: a second factor at sign-in, recognition of the devices you use, and re-verification of your password before it can be changed. Each is described below, including its limits.
Enabling two-factor authentication
Enable it in Settings, under Security. Enrollment requires scanning a QR code, so it is performed in the browser; once enabled it is enforced everywhere, including in the Mac and iPad applications. Any standard authenticator application works, including Google Authenticator, Authy and 1Password.
The code is generated on your device and verified on ours. Nothing is sent by email or SMS, so there is no message to intercept. Where no authenticator is configured, a six-digit code is sent to the address on the account instead.
Where the second factor is checked
On every request to your content, not only at the sign-in form. A session that has not satisfied the second factor does not reach your manuscripts, so a session token copied from a signed-in browser is not sufficient on its own. Disabling two-factor authentication requires your password.
Recognized devices
Signing in from a browser Calamus has not seen requires one additional verification. Answering it recognizes that browser for 30 days, after which it verifies again. An emailed verification code expires after ten minutes, is bound to the browser that requested it, and can be used once.
Settings, under Security, lists the devices your account is recognized on, with the time each was last seen and when its recognition expires. Revoking one takes effect immediately and can be done from any device. Revoked and expired entries remain in the list, so the history of access to the account stays readable.
The limit worth knowing
Recognition expires with the device cookie and not before. A laptop that is lost or stolen therefore remains recognized for the remainder of its 30 days unless it is revoked. Revoking it is the action that ends that access, and it is available from any other device on the account.
A recognized device appearing on a different network is recorded and nothing further happens. You are not asked to verify again for travel, for a virtual private network, or for a change of country.
Changing your password
Settings, under Security, requires your current password, the new password, and a confirmation. The current password is verified before the change is saved. Repeated failed attempts are throttled by IP address and by account.
What is recorded
Sign-ins, failed sign-ins, device verifications and revocations, export downloads and account deletion are written to a security log with the originating IP address and browser. It contains no part of your writing, and no screen displays it. Every field is listed in the Privacy Policy.