Account security
The ways you can sign in to SIMCOAI, and which to choose for an account that can spend money and read customer conversations.
Where signing in happens
Choosing to sign in takes you to a SIMCOAI-run sign-in address — id.simcoai.co.uk. It is SIMCOAI’s own, not a third-party page you have been handed off to, and it is the same account throughout — there is nothing separate to register.
It is a separate address on purpose. Passwords, one-time codes and sign-in links are handled entirely by that service, so they never pass through the dashboard or through your workspace. When you reset or change a password, you set the new one there and it is never sent to, or stored by, the rest of SIMCOAI.
Your business data — your profile, customers, bookings, calls and conversation history — stays in SIMCOAI’s own database and is linked to your account by an identifier, not by your password.
- Signing in: you are taken to your account’s sign-in address and returned to your dashboard once you are in.
- Changing your password: Security in the dashboard emails you a secure link. The form does not ask for the new password, because your workspace is not where it is set.
- Signing in with Google: there is no separate SIMCOAI password on your account at all, and the dashboard tells you so rather than offering to change one.
- Where your password lives: only on the sign-in service. SIMCOAI holds no password record for your account, in any form.
- Where you change things: sign-in methods are added and removed on the sign-in page itself, not inside the dashboard, so a change applies everywhere rather than to one browser.
If you ring our support line about your account
The line can send you a password reset link, and that is the only thing it does to an account. The link is delivered to the mailbox you name and is useless to anyone who does not already control it, so it needs no further check — it grants nothing that the reset link on the sign-in page does not already grant any visitor. It answers the same way whether or not that address has an account, so nobody can use it to work out who banks with SIMCOAI.
- We cannot read your password, and neither can anyone else. It is held as a one-way scramble. There is no screen, export or support tool anywhere that returns it — this is not a permissions limit we could lift.
- We will not set a new one for you. Not on the phone, not by email. You set it yourself through the reset link.
- Two-step verification, passkeys and security keys are never removed by phone, nor is the email address on an account changed or an account unlocked. Those are precisely what somebody impersonating you would ask for, so they go to a person who verifies you first.
- We will never ring you and ask for a password, a one-time code, or to approve a prompt you did not start. If somebody does, it is not us. End the call and ring the published number.
Sign-in options
| Method | Strength | Notes |
|---|---|---|
| Passkey | Strongest | Available now. Phishing-resistant, nothing to type. Choose Continue with a passkey when you sign in. Bound to your device unless your platform syncs them. |
| Authenticator app | Strong | Time-based codes. Supported by the sign-in service; ask us to switch it on for your account. |
| Security key | Strong | A physical key such as a YubiKey. Supported by the sign-in service; ask us to switch it on. |
| Google sign-in | Good | Security follows your Google account, including its own MFA. |
| Magic link | Convenient | Single-use and short-lived. Mail scanners can consume links before you do. |
What we suggest
- Add a passkey on the device you use most, and keep a second method as backup. This is the strongest option available today and takes one tap at sign-in.
- Keep your password as the backup if you add a passkey, so losing the device does not lock you out.
- Do not share one login across a team - individual accounts mean the audit trail is meaningful.
- Remove access when someone leaves. This is the most commonly skipped step.
Things SIMCOAI will never do
If you cannot get in
See login problems. Support cannot bypass MFA for you - that is the point of it.