Registration and first setup
- Registration creates an individual account, an organization workspace, an owner membership, and an Explorer subscription record.
- Email verification is required before website setup, paid Checkout, team invitations, and other protected operations.
- The first website must be verified through DNS, a homepage meta tag, or a public verification file before a full audit can run.
- Explorer does not require a payment card and includes one verified website with up to 250 audited pages each month.
Organizations and teams
- A person can belong to more than one organization and switch the active workspace.
- Owner, administrator, billing, member, and viewer roles separate organizational, billing, operational, and read-only responsibilities.
- Pending invitations count against the plan seat limit so invitations cannot bypass entitlements.
- Only authorized roles can invite members, manage billing, archive websites, or create protected operational records.
Account security
- Passwords are stored as secure hashes and are never retained in plain text.
- Repeated failed sign-ins trigger temporary lockout controls.
- Authenticator-based MFA and one-time recovery codes are available for additional protection.
- Active sessions can be reviewed and revoked from the security page.
- Verification and password-reset links are single-use and expire automatically.
What this FAQ covers
This page answers recurring questions about accounts, workspaces, and access for website owners, agencies, and technical teams. The answers define practical boundaries, identify the evidence that matters, and explain when a question requires account-specific, technical, contractual, or legal review.
- What is created when I register?
- Why is email verification required?
- Why must I verify the website?
- Can I belong to more than one organization?
Use the answers responsibly
Apply each answer to the actual website, scope, agreement, and evidence. Avoid overstating a scanner result as a confirmed exploit. When the decision could affect production availability, security, accessibility, billing, privacy, or contractual commitments, document the responsible reviewer and verification plan.
Expand the reach of Accounts, workspaces, and access
Search visibility and user value improve when accounts, workspaces, and access answers the real questions people bring to the page. For website owners, agencies, and technical teams, that means covering the decision context, observable signals, implementation boundaries, and proof that the result works in production—not repeating a keyword or publishing a longer version of the same incomplete explanation.
Use the page as part of a connected topic cluster. Link the broad concept to focused implementation guides, definitions, checklists, examples, and the Asuruas workflow that can identify affected URLs. The goal is to help a reader move from discovery to a confident next action while giving search systems clear entities, relationships, and page purpose.
- Inspect transport and certificate posture.
- Inspect response headers and browser policy.
- Inspect exposed software and dependency signals.
- Inspect authorization boundaries and sensitive endpoints.
Strengthen the answer
Correct high-confidence configuration weaknesses first.
Build the topic cluster
Separate observable signals from exploitability claims.
Prove the outcome
Retest externally after the production change.
Questions and answers
01What is created when I register?
Registration creates an individual account, an organization workspace, an owner membership, and a free Explorer subscription record.
02Why is email verification required?
Verification confirms the address used for website setup, invitations, billing, recovery, and protected operations.
03Why must I verify the website?
Website verification demonstrates control through DNS, a homepage meta tag, or a public file before Asuruas permits a full audit. It does not expand your authorization beyond the agreed scope.
04Can I belong to more than one organization?
Yes. A person can have memberships in multiple organizations and switch the active workspace, subject to the role assigned in each one.
05Which roles are available?
Owner, administrator, billing, member, and viewer roles separate organization, billing, operational, and read-only responsibilities.
06How are passwords stored?
Passwords are processed with the application password-hashing framework and are never stored or emailed as readable text. Reset links are single-use and time-limited.
07Do pending invitations count against seat limits?
Yes. Pending invitations count against the plan seat limit so invitations cannot bypass plan capacity.
08How is account access protected?
Passwords are securely hashed, repeated failures trigger temporary lockout controls, authenticator-based MFA is available, recovery codes are one-time use, and active sessions can be revoked.
09Who can change billing or invite members?
Only roles authorized by server-side permission checks can perform billing, invitation, website, audit, or organization-management actions.
Turn accounts, workspaces, and access into an accountable record.
A clear, supportable answer set for accounts, workspaces, and access linked to the relevant workflow or policy.