# Security

> Review your account security status and change your password.

The Security section shows your account's current security status and lets you change your password. You can also review best-practice recommendations to keep your account protected.

Navigate to **Settings → Security** or go to `?section=security`.

<!-- screenshot: settings/security-settings -->

## Account security status

The status card at the top of the page shows:

- **Email verified** — confirms your sign-in email address has been verified
- **Account type** — shown as "Business User"
- **Signed in as** — your email address and the time of your last login

## Change your password

1. Click into the **Change password** form.
2. Enter your current password.
3. Enter your new password — at least 8 characters, mixing uppercase, lowercase, numbers, and special characters.
4. Confirm your new password.
5. Click **Update password**.

Your session remains active after a password change. Other active sessions (for example on a different device) are signed out automatically.

## Security recommendations

The page lists four practices worth keeping in mind:

| Recommendation | Why it matters |
|---|---|
| Use a strong, unique password | Prevents credential-stuffing attacks if another service is breached |
| Keep your email address current | Your email is used for password resets and security alerts |
| Sign out of shared devices | Prevents unauthorized access from public computers |
| Monitor your account activity | Lets you catch unexpected sign-ins early |

## If you suspect unauthorized access

Change your password immediately using the form above, then contact [Caramel support](../resources/troubleshooting). Do not share your login credentials with anyone — support staff will never ask for your password.

## Session IP locking

Some accounts have access to advanced session security controls that bind your login sessions to trusted IP addresses or ranges. If this feature is available on your account, it appears within the Security section. See your account settings to check availability.

## Related

- [Owner alerts](./owner-alerts) — add a phone number for urgent account alerts
- [Team & Permissions](../team/index) — manage which team members can access your workspace
