Members must maintain reasonable control of authentication credentials, authentication factors, devices, recovery methods, and other means of account access.
DIY Finance may use passwords, passkeys, email verification, third-party identity providers, multi-factor authentication, device/session controls, risk-based verification, and step-up authentication. Specific methods may change over time.
Authentication assurance may increase with the sensitivity or consequence of an action. Higher-risk actions may require re-authentication or a stronger enrolled factor. Lower-risk account access may use lower-friction verification where appropriate.
DIY Finance may restrict or suspend access, require additional verification, revoke sessions, or take other protective measures when fraud, account takeover, misuse, security risk, or legal obligations are reasonably suspected.
Members should promptly report suspected unauthorized access through the Member Service Center. Account-recovery procedures may require identity verification and may limit access while a request is reviewed.
No authentication or security method can guarantee that unauthorized access will never occur.