2 min read
Why review your sessions
Every time you sign in on a new browser or phone, your account records that device — its type, rough location and when it was last active. This list is a mirror of who currently has your account open. If you ever see a device or location you do not recognise, that is a warning sign you can act on immediately, before any damage is done.
How to review and remove
- Open Security settings and go to Devices and sessions.
- Read down the list. Each entry shows the device, the approximate location and when it was last used.
- For anything you do not recognise, choose Sign out — that ends the session on that device straight away.
- If you are unsure about several, choose Sign out of all other devices and sign back in only where you need to.
If a device is lost or stolen
If your phone or laptop goes missing, sign in from another device and remove the missing one from the session list right away. Then change your password and confirm two-factor authentication is active, so even someone holding the device cannot get back in. If the lost device held a passkey, remove that passkey too.
Trusted devices and 2FA prompts
You can mark a device you own as trusted so it does not ask for a 2FA code every single time for a set period. Only do this on devices only you use — never a shared or public computer. On a shared machine, always use a private window and sign out fully when you finish.
Frequently asked questions
What does 'sign out of all other devices' do?
It ends every active session except the one you are using, forcing a fresh sign-in everywhere else. It is the quickest way to lock out anything you do not control.
Why does the location shown look wrong?
Location is estimated from the network address and can be off by miles, especially on mobile networks or VPNs. Judge by the device type and timing as well as location before acting.
Will signing out other devices log out my colleagues?
It signs out other sessions of your own login. Colleagues have separate logins, so their sessions are unaffected unless they share your credentials — which they should never do.
Related reading

Securing your Credit Corp business account: the full guide
The single place to lock down your Credit Corp business account — covering the password, two-factor…
Read →
Setting up an authenticator app for two-factor authentication
Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from…
Read →
Reporting a lost or stolen device
If a device with access to your account goes missing, act in this order: sign out the device remotely, change…
Read →
Managing user roles and permissions
Roles let you give each colleague the right level of access: some can only view, some can transact, one is…
Read →Funding for UK limited companies
Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.