At Verto, keeping your funds and company account secure is our highest priority. To protect your organisation against Account Takeover (ATO) attempts and unauthorised access, we utilise advanced security controls including New Device Detection, Multi-Factor Authentication (MFA), and automated account safeguards.
1. Logging In & Device Security
What happens when I log in from a new device or location?
When our system detects a login attempt from an unrecognized browser, phone, or location, it automatically triggers Elevated MFA to verify your identity:
Step 1: You will be prompted to enter a code from your Authenticator App (TOTP), SMS, or WhatsApp. Note: Email OTPs are disabled for this step to ensure a compromised email account cannot be used to gain access.
Step 2: You will then be asked to provide a secondary verification code using a different method (such as Email, SMS, or WhatsApp) to complete the login.
Will I have to do this every time I log in?
No. To ensure a smooth onboarding experience, the very first device you use when joining Verto is automatically recognized as a trusted device. Elevated MFA will only trigger when you log in from an unfamiliar browser, a new device, or a different location.
How can I view or manage my trusted devices?
You can view and manage all devices currently logged into your account at any time:
Navigate to Settings > Login Activity on either Web or Mobile.
Review the list of active sessions and trusted devices.
Click "Sign out" next to any unrecognized or old device to immediately terminate its access.
2. Account Alerts & Emergency Lockdown
What should I do if I get a "New Device Login" notification that wasn't me?
Whenever a new device logs into your account, an automated alert email is sent to you. If you do not recognize the activity:
Open the email and click "No, secure my account."
A browser tab will open asking you to confirm your selection to prevent accidental account freezes.
Once confirmed, the system immediately locks down your profile to protect your funds.
What happens during an Emergency Lockdown?
Depending on your user permissions within your company, the system takes immediate protective action:
Standard Users (Approvers & Readers): Your individual account is instantly locked, and all active sessions across all your devices are terminated. Your company's primary account remains active so day-to-day operations can continue.
Super Admins & Admins: Because administrative accounts hold higher access permissions, the entire company profile is temporarily set to inactive and all active team sessions are ended to prevent organization-wide fraud.
How do I unlock my account after an emergency lockdown?
If your account has been locked, your company's Super Admin will be notified, and our Security Team will be alerted immediately. To regain access, please contact Verto Customer Support to complete a brief identity verification check.
3. Password Changes & Security Holds
Why can't I make payments or update beneficiaries after changing my password?
Following any password change, a 24-hour security cool-off period is automatically applied to your profile. During this window:
You can still log in and view account balances.
High-risk actions—such as processing outbound payments, adding new beneficiaries, or modifying user settings—are temporarily blocked.
This delay prevents unauthorized users from changing your credentials and immediately transferring funds out of your account. Full account functionality automatically resumes once the 24-hour period ends.
Will I ever need to enter an Authenticator code on a trusted device?
Yes. For your protection, critical actions (such as changing your password or adding a new user to your organization) always require mandatory Authenticator App (TOTP) confirmation, even when operating from a trusted device.
4. Recovering Lost MFA Access
What should I do if I lose my phone and can't access my Authenticator App?
If you lose your device or change phones and can no longer generate authenticator codes, your MFA enrollment must be reset:
Contact your Client Super Admin: Your company's Super Admin can clear your authenticator setup directly from their administration dashboard, allowing you to register a new phone on your next login.
Contact Verto Support: If you are the sole Super Admin on the account, contact Verto Customer Support, and our team will guide you through our secure identity verification process to reset your MFA.
