A little paranoia is just good housekeeping

Keep the keys to the collection in good hands.

A collection can reveal what you own, what it is worth, and where it lives. KolleK gives you practical ways to protect access without turning account setup into an evening activity.

Two-factor authentication STEP 2 OF 3

Scan in your authenticator

Or enter this setup key manually:

KZ4F · 9QM2 · 7T8W · X1RC

Recovery codes

4f2a-9c1e b83d-77kk p0m2-x4rt 9zq1-6h5v tt4c-1b8n e7w3-2ky9
Store these somewhere safe, not next to your phone.

Add a second factor

A stolen password stops being enough.

Turn on two-factor authentication and one leaked password no longer opens the door. Keep the recovery codes somewhere safe, ideally not in the same place as the phone that generates the codes.

Authenticator app

Time-based codes from any TOTP app. Scan the QR once and you are set.

Recovery codes

One-time codes for when the phone is lost. Kept off-device, on purpose.

Breached-password check

New passwords are checked against known breaches before they are accepted.

Sign in without another password

Let your inbox do the vouching.

Magic links let you sign in from your email when that is more convenient. Less password wrangling, fewer “which one did I use?” moments.

15-minute expiry Single use Ignore-to-cancel

Sign in to KolleK

no-reply{{ Str::lower(config('app.name')) }}.app · to jamie@…

now

Here is your one-time sign-in link. It expires in 15 minutes and can only be used once.

Sign in to KolleK

Didn’t request this? You can safely ignore it, nothing changes until the link is used.

Signed in securely

MacBook Pro · Portland, US · 2FA verified

Trusted device

Know when something looks off

The first hint should come from us.

KolleK emails you about failed sign-ins, new devices, changed IP addresses, and API-key changes. The first time you learn about a strange login should not be from a stranger.

Security notifications Last 7 days
New device signed in New device

Chrome on Windows · Denver, US · verified with 2FA.

2 hours ago
Sign-in from a new IP address IP change

Location changed from Portland to Denver, US.

2 hours ago
API key created API key

Key “export-script” created with read-only scope.

Yesterday
Failed sign-in attempts Blocked

3 failed attempts on your account, then rate-limited.

3 days ago
Every alert is emailed the moment it happens, no dashboard-watching required.

Make good choices easy

Every control in one place.

Security settings put passwords, two-factor authentication, recovery codes, API keys, and account protection together. The controls are there before you need them.

Settings · Security Strong

Password

Last changed 4 months ago · checked against breaches

Strong

Two-factor authentication

Authenticator app · 6 recovery codes remaining

On

Magic-link sign-in

Sign in with a one-time email link

On

Security alert emails

New logins, IP changes, and API-key events

On

API keys

1 active key · read-only scope

Manage

Turn on the protection while it is quiet.

Two-factor, recovery codes, magic links, and actionable alerts, set them once from one settings page.

Review your security settings

KolleK might not be for you (yet) if…

You require SSO, hardware security keys, or a full enterprise identity platform.

You need end-to-end encryption.

Choose KolleK when…

You want strong everyday account protection without turning setup into a project.

You want two-factor authentication, recovery codes, magic links, and actionable security alerts.

Encryption at rest is covered on the data ownership page; this is not end-to-end encryption. The feature status page has the boring-but-important details.