LogoCRANIX
Home Products Support

Security

How Cranix protects your account

One Cranix account signs you in to every Cranix app, so keeping it safe matters. Here is exactly what is in place — no vague reassurances.

Your password

Passwords are hashed with bcrypt and never stored in a form anyone — including me — can read. When you set or change one it is checked against the Have I Been Pwned breach database (using k-anonymity, so your password never leaves your device in the clear); if it has turned up in a known breach, Cranix refuses it and asks for a stronger one.

Two-factor authentication

You can turn on 2FA with any authenticator app — Microsoft Authenticator, Google Authenticator, Authy, 1Password, and so on — and you get one-time backup codes to keep somewhere safe in case you lose your phone.

Sessions & devices

From your account page you can see every device that is signed in and sign any of them out, or all of them at once. Signing out, changing your password, or a staff action revokes the session on the server immediately — not "eventually".

Brute-force protection

Repeated wrong passwords lock an account for a cooldown, and sign-in attempts are rate-limited, so nobody gets to sit there guessing.

One account, guarded everywhere

Because the same account works across Cranix One, Player, Notes and Scout, a sign-out or a security action applies to all of them at once — there is no forgotten side door.

Your data is yours

You can download everything Cranix holds about you, or delete your account outright, at any time from your account page — no email, no "contact us to cancel". See Transparency for what is stored and why.

Found a problem?

If you think you have found a security issue, please tell me before anyone else — head to Support and flag it as a security concern. I read those first.

© 2026 Cranix. All rights reserved.
Why Cranix · Security · Transparency · FAQ
Privacy Policy • Terms of Service