SECURITY

Account and Payment Security

Keep account access, payment information, and API credentials secure.

Review every authorization request

Approve a device only when you started the sign-in. Confirm that the code in your browser matches the code shown by the application.

Keep credentials private

Never share:

  • Passwords.
  • Full card details.
  • API keys.
  • Access tokens.
  • Refresh tokens.
  • Device authorization codes.

A MaxLabs administrator or support representative should not ask you to send these values in chat or email.

Remove old device access

Remove saved accounts from devices that you no longer use. Company administrators should also remove members who no longer need access.

Report unexpected activity

If you see an unknown payment, account connection, or usage record, stop using the affected credential and contact support. Include non-sensitive payment or invoice identifiers so the team can investigate.