Secure the administrator area first
- Use a unique password and enable two-factor authentication.
- Create separate administrator accounts instead of sharing credentials.
- Assign only the permissions each person needs.
- Review active device sessions and revoke unfamiliar access.
- Use HTTPS and keep server, PHP, database, and Model Hub Pro releases current.
- Review login, configuration, licensing, payment, and audit logs.
Trusted-device sign-in
Persistent sign-in can restore an expired session on a trusted device, but sensitive administrator actions still require recent password verification. Sign out and revoke devices after using a shared or lost computer.
Incident response
If compromise is suspected, disable access, rotate passwords and API credentials, revoke sessions, preserve logs, inspect file changes, and restore only from a known-good backup.
