Skip to main content

Access Recovery

At Bron, your security is our top priority. We use a multi-layered MPC-based system to protect your account and assets. But access issues happen — lost devices, forgotten passkeys, or compromised shards.

Access on Bron works on two independent levels, and each has its own recovery:

  • Level 1 — Signing in to your account. Your passkey (and 2FA, if enabled) protects access to the Bron app: workspaces, balances, settings.

  • Level 2 — Signing transactions. Transactions are signed with key material stored on your trusted device. Signing in alone is never enough to move funds.

Recovering one level does not automatically restore the other — so compromising one of them is never enough to take over your assets.

1. Recovering access to your account (lost passkeys and/or 2FA)

If you’ve lost the passkeys you use to sign in, start recovery from the Login page → Use another account → Lost access. There are three ways, depending on what you have set up — see the Account Recovery: Step-by-Step Guide:

  • FaceScan — the fastest way. Verify your identity with a face scan; if any of your workspaces has ever moved $100 or more, access is restored automatically after a 2-day security delay, otherwise right away.

  • Guardians — enter recovery codes from 2 of your Guardians, then a 2-day security delay runs and access is restored automatically.

  • Self-recovery — if neither FaceScan nor Guardians can verify you, you can still recover on your own after an extended delay: 30 days if any of your workspaces has ever moved $100 or more (14 days with a valid 2FA code), otherwise 2 days.

⚠️ Newly added Guardians or a newly set up FaceScan must first pass a 30-day security delay before they can be used for recovery. For a Guardian the 30 days start when that person accepts the invite; for FaceScan, when the enrolment is completed. Until then, the method is shown as unavailable, with the time remaining until it becomes available.

If you have 2FA set up, you will be asked to enter the code or mark it as lost; a lost 2FA extends the delay (for example, from 2 days to 7).

2. Restoring signing (lost or compromised trusted device)

If the device you use to sign transactions is lost, reset, stolen, or compromised — or you have changed its biometrics: re-enrolling Face ID, Touch ID, or Windows Hello invalidates the key shards stored on the device and removes its trust — restore signing on a new device: install the Bron desktop or mobile appDevices ManagementTrust this device. There are four options:

  • Approval from another trusted device — if you (or a teammate) still have a working trusted device, no recovery is needed: simply approve the request from that device.

  • FaceScan — verify your identity with a face scan; signing is restored after a 48-hour security delay.

  • Guardians — enter recovery codes from 2 of your Guardians; signing is restored after a 48-hour security delay.

  • Self-recovery — no FaceScan or Guardians available: a 30-day security delay applies.

⚠️ Any of the three recovery options (unlike approval from another device) removes all other trusted devices — after recovery, only the new device can sign. The 30-day security delay for newly added Guardians or FaceScan applies here as well — for a Guardian it starts when that person accepts the invite.

Need help?

Each recovery flow is tailored to balance security and ease of access. If you’re unsure which method to use, or if your situation doesn’t match the above, contact our support team via messenger on the Bron platform, Bron Help Center or by email support@bron.org — we’ll guide you through the safest way to restore access.

Did this answer your question?