Security and trust at Staylist

How ApexOS keeps the wrong people out.

Passkeys, two-step verification, sign-in rules you set for your whole team, and firm limits on what Staylist’s own staff can do. Everything below is in ApexOS today.

01

Signing in

Stronger ways in than a password, and no codes sent by text or email.

  1. Passkeys, up to 10 per person

    Each person can add up to 10 named passkeys to their own profile and use them in every account they can reach. Removing one asks them to confirm first.

  2. Sign in with only a passkey

    Your team can sign in with a passkey alone, from a button or the browser’s passkey autofill. No email or password to type.

  3. Google or Microsoft

    Team members who already have an ApexOS user can sign in with their Google or Microsoft account.

  4. Two-step verification without text messages

    When two-step verification is on, ApexOS asks for an authenticator app code, a passkey or a single-use recovery code. It never texts or emails your team a sign-in code.

  5. Recovery codes that work once

    Setting up an authenticator app creates single-use recovery codes. They are shown only until you confirm you saved them, and you can make a new set at any time.

  6. Lockouts and deactivated users

    Repeated wrong passwords lock sign-in for a while, though a passkey still works. Deactivated users can’t sign in at all.

02

Rules you set for your team

Decide who has to use strong sign-in, and make the risky changes ask twice.

  1. Require strong sign-in

    An organization can require an authenticator app or passkey for no one, for its admins and account owners, or for everyone. People get 7 days to set one up.

  2. Properties can tighten the rule, never loosen it

    Each account inside an organization follows the organization’s rule. It can choose a stricter one, and a weaker choice is refused.

  3. Nobody drops their last factor

    If your rule requires strong sign-in, ApexOS won’t let anyone remove their last authenticator app or passkey until they add another.

  4. Risky changes ask for a fresh check

    Inviting team members, changing roles and permissions, removing, activating or deactivating people, and changing the sign-in rule all need a password or passkey check from the last 15 minutes. Each one is logged.

03

What Staylist can and can’t do

The limits on our own staff, and what we do when an account may be at risk.

  1. Our staff use strong sign-in too

    Staylist staff can open a customer account only after signing in with an authenticator app or a passkey.

  2. We can freeze access fast

    If an account may be compromised, Staylist security staff can freeze a user’s access. Every sign-in method is blocked, every session ends and the user is told. Lifting the freeze doesn’t sign them back in.

  3. Lost every sign-in method? Support resets it

    Only Staylist support can reset a person’s sign-in methods. Not the person, and not your own admins. A reset removes every passkey, authenticator and recovery code and signs out every session.

A security questionnaire, or a question this page doesn’t answer?

Send it to us. We’ll answer in writing, from what the product does today.

Contact us
ApexOS security FAQs

Questions teams ask us.

Can I require two-step verification for my whole team?

Yes. An organization can require an authenticator app or a passkey for no one, for its admins and account owners, or for everyone. People get 7 days to set one up, and each property can choose a stricter rule but not a weaker one.

Does ApexOS send sign-in codes to my team by text or email?

No. Two-step verification for your team uses an authenticator app code, a passkey or a single-use recovery code. ApexOS never texts or emails your team a sign-in code.

Can my team sign in without a password?

Yes. Anyone can sign in with a passkey alone. Team members who already have an ApexOS user can also sign in with Google or Microsoft.

Can Staylist staff get into my account?

Staylist staff can open customer accounts, and they must sign in with an authenticator app or a passkey to do it. Staylist security staff can also freeze a user’s access if an account may be compromised.

What happens if someone loses their phone and their passkeys?

They can sign in with one of their single-use recovery codes. If those are gone too, Staylist support resets their sign-in methods. Your own admins can’t do that reset, and the person can’t do it themselves.

Book a demo

Bring your security questions to the demo.