1. Security practices
DWL Accounts supports Google sign-in, passwords, email codes, and passkeys. Connections are encrypted, passwords are stored in a protected form, and account changes require an authenticated session or verification. Access to account information is restricted to the people and services that need it.
In Security, you can review sign-in methods, manage your password and passkeys, and check account activity. Account alerts report security and account changes. In Apps, you can review and remove app connections.
2. User security responsibilities
- Use a unique password or a passkey and keep your devices locked.
- Protect your email account; it is used for sign-in codes and recovery.
- Sign out on shared devices and remove passkeys you no longer use.
- Review unfamiliar account alerts and app connections.
Report suspected account compromise or unauthorized activity to security
3. Responsible disclosure
Send suspected vulnerabilities to security
4. Security incidents
We investigate incidents affecting personal information, account security, or connected-app access and provide notices where required by law or applicable provider rules. Include your account email and a description of what happened when reporting an incident. This inbox is not an emergency service.
5. Security boundaries and no warranty
Public security statements describe intended controls and do not create a warranty, guarantee, certification, audit representation, or promise that a specific configuration is active at all times. Do not rely on DWL Accounts for emergency, life-safety, regulated healthcare, regulated financial, or mission-critical workflows unless a separate signed agreement and reviewed implementation expressly say otherwise.