Skip to main content

Security Centre

Your security level, the recommended safeguards, and every protection in one place — Settings → Security.

The Security Centre is the one page that answers "is my workspace actually protected?". It scores your current setup, tells you what is missing, and links straight to every control — funds protection, policies, recovery, personal security and devices.

Open it from Settings (the gear icon in the top bar) → Security. On mobile: your avatar → ProfileSecurity.

1. Your Security Level

The gauge on the right gives your workspace one of four levels. It is not a score out of ten — each level is a gate, and you reach it only when every item below it is in place.

Critical — you have no way to recover access. This is the level to leave today.

Medium — you can recover access, but withdrawals are not protected yet. To reach it, set up a recovery method: either two Guardians or FaceScan. Either one is enough.

High — withdrawals and limit changes are protected. To reach it, add on top of the above:

Very high — everything Bron offers is switched on. On top of the above:

  • Address book lock and New address withdrawal lock

  • the Manage address book, Manage users and Manage owners policies

  • 2-Step Verification on your own account

The level is worked out live from your current settings — nothing is cached, so it moves the moment you change something.

1.1 The Warning Banner

Below the header you may see a banner: Your security level is low at critical, or Your security level is medium. Both offer a button that takes you straight into the recommended actions, and a Dismiss button.

Dismiss only clears the banner for now — it comes back next time you open the page, and it does not change your settings. At Very high no banner appears at all.

There is one extra variant: if you are at High but have no Guardians (you used FaceScan instead), the banner suggests assigning Guardians as a second recovery route.

2. Improve Security In One Click

Press Improve security (or Protect now at critical level) and the Maximise security popup opens. It lists only what is currently off in your workspace, split into two groups.

2.1 Enabled Automatically

Press Enable protection and Bron applies these for you:

  • Address book lock — only allow sending to addresses saved in your address book. Applied immediately.

  • New address withdrawal lock — prevent sending to newly added addresses for 48 hours. Applied immediately.

  • All security policies — any of the Manage address book, Manage users and Manage owners policies that are off get switched on with a 48-hour security delay as their protection method.

💡 Two things worth knowing. The policies are enabled with a security delay, not user approval — no approvers are assigned, so nobody has to be available for a change to eventually go through. And the Manage transaction limits policy is not part of this action: turn that one on yourself in Security Policies.

If you would rather pick approvers instead of delays, use Customise it next to "All security policies" — it opens the policy editor for those same three policies, where you can choose User approval and set who approves.

2.2 Complete Your Setup

The second group is what only you can do — one click cannot set these up for you:

  • 2-Step Verification — protect your account with a time-based code from your authenticator app.

  • Assign two Guardians — trusted people who can help you recover access.

3. Funds Protection

Everything that controls how assets leave the workspace.

Transaction limits — shows how many limits are active, for example 1 limit applied. Opens Transaction Limits.

Address book lock — allow withdrawals only to saved addresses. Shows an Enable button while it is off.

New address withdrawal lock — this row only appears once the lock is on, as confirmation. To switch it on, use Improve security or the Other block in Security Policies.

4. Security Policies

A summary of which critical changes are protected by an approval or a delay, each shown as On or Off: Manage transaction limits, Manage address book and Manage users.

Manage owners is deliberately not in this summary — use Manage all policies to see and configure all four, the Policy change rule and the Other settings. Full details in Security Policies.

5. Recovery

How you get back in if you lose your device. If neither method is set up, this card shows a warning — at that point your security level is Critical.

Guardians — trusted people who can help you recover access. You need two assigned for this to count as a recovery method. See Access Recovery.

FaceScan — verify your face to recover access, as an alternative or a complement to Guardians. Verification runs through iProov, a third-party provider, and your face is never stored as a photo. Once set up, the row shows when it was added.

💡 FaceScan is being rolled out gradually, so the row may not be there yet for your workspace. Guardians are available to everyone.

6. Personal Security

This card is about your own account, not the workspace.

Passkeys — how you sign in. The row shows how many you have; add a second one so a lost device doesn't lock you out.

2-Step Verification — a time-based code from your authenticator app, on top of your passkey. It is required for the Very high level and takes about a minute to set up.

7. Linked Devices

Your active sessions, grouped into Session on computer and Session on mobile with a device count each. Manage all devices opens the full list, where you can end a session you don't recognise.

8. Monthly Security Checklist

The right rail holds four things worth re-reading every month. Nothing here is a task you tick off — each row shows the current state and opens the place to review it.

  • dApps and spending caps — active dApp connections and token allowances, or No connection yet. Old allowances are a common way funds leak, so this is the row to check first. See dApp Connect.

  • Members permission — how many users have access. Opens Users, where you can deactivate anyone who no longer needs it.

  • Trusted devices — which accounts hold device shards. See Managing Trusted Devices. Viewers don't see this row.

  • Linked devices — your active sessions, same list as the card above.

9. Your Assets Are Protected

Under the checklist sits a short note on how Bron holds your assets: Bron uses open-source Multi-Party Computation (MPC). No private key is ever created — shards work together to approve transactions. For the full picture see MPC Security.

The header also carries two shortcuts: Hide account, which walks you through hiding an account behind a PIN, and Get help, which opens our security documentation.

10. What Each Role Sees

The Security Centre is available to every user with access to accounts, but the actions are not.

  • Owners see and can change everything on the page.

  • Members and Viewers can review the page and manage their own passkeys, 2-Step Verification and sessions, but cannot change workspace policies or locks — those buttons are disabled with the reason shown.

  • Viewers additionally don't see the Trusted devices row.

  • Users with no account access — Guardians and Beneficiaries — are taken to Access & recovery instead.

11. Where To Start

If you are opening this page for the first time:

  1. Assign two Guardians, or set up FaceScan. This is the one that matters most — without it, nobody can help you recover access.

  2. Set one transaction limit — a daily cap with a security delay is a reasonable first rule.

  3. Turn on the Policy change rule, then the Manage transaction limits policy.

  4. Press Improve security and let it enable the locks and the remaining policies.

  5. Set up 2-Step Verification and add a second passkey.

That takes you from Critical to Very high, and the gauge will confirm it.

If you have questions, contact our support team via messenger on the Bron platform or by email support@bron.org.

📅 Questions about how this works for your team? Book a call with our product team

Did this answer your question?