Back to news
Product update14 August 2026

Greater Control Over Your Account Security on PortfolioReach

Active sessions, passkeys, and additional verification give PortfolioReach users greater control over access to their accounts.

Preview of PortfolioReach account security settings with active sessions, passkeys and extra verification
PortfolioReach account security settings preview.

Account security shouldn't stop at a password.

That's why we've expanded PortfolioReach's security settings with new features that give you greater control over where your account is signed in and how access to it is protected.

See Your Active Sessions

You can now view the active sessions associated with your account directly in your security settings.

Each session is handled independently, allowing you to see information such as:

  • whether it is your current session,
  • when it was created,
  • when it was last active,
  • which browser or client was recorded for the session,
  • the approximate country of the most recent activity.

We do not display your full IP address in the user interface.

If you see a session you don't recognize, you can sign it out. You can also sign out all other sessions at once while keeping only your current browser session active.

Passkeys and Security Keys

We've also added support for passkeys based on the WebAuthn standard.

This means your account can be further protected using authentication methods supported directly by your device or browser.

For example:

  • Windows Hello,
  • a physical security key such as a YubiKey,
  • a compatible passkey stored on your device or synchronized through a supported ecosystem.

Each passkey you add appears separately in your security settings. You can give it your own name, see when it was added and last used, and remove it whenever necessary.

This means a physical security key can become another layer of protection for your PortfolioReach account.

Additional Verification for Important Changes

Having an active session alone should not always be enough to perform particularly sensitive actions.

That's why we've introduced additional security verification for selected actions, including:

  • changing your password,
  • managing two-factor authentication,
  • managing passkeys,
  • signing out other sessions,
  • deleting your account.

Depending on your account configuration, you can confirm these actions using a passkey or existing security methods such as your password, a TOTP code, or a recovery code.

Passkeys do not currently replace your password entirely. We keep the existing account recovery methods available rather than making access to your account dependent on a single device or security key.

Sessions, Trusted Devices, and Passkeys Are Different Things

We've also clearly separated three security concepts that are often confused with one another:

An active session represents a specific sign-in through a browser or another client.

A trusted 2FA device allows you to temporarily skip entering an OTP code again on a known device.

A passkey is a cryptographic credential used to verify your identity.

Each of these can be managed separately.

Security Grows Together With PortfolioReach

PortfolioReach is still a young platform, but from the beginning we want to build features that often only appear as larger platforms mature.

The new security system was introduced gradually and tested with Windows Hello, a physical YubiKey, and multiple browsers.

And we're not stopping here.

We'll continue developing tools related to account security, session protection, and keeping users informed about important security events.

Your portfolio should showcase your work. Access to it should belong only to you.