New: Professional PDF proposals now include client e-approval tracking. See what's new →
Home
  • Pricing
  • About
  • Quick Start Trial
    🔐 Security & Data

    Enable Two-Factor Authentication (2FA)

    Add an extra layer of protection to your QuickEstimate account by setting up 2FA via an authenticator app or SMS verification.

    Protect Your Account in Minutes

    Two-factor authentication (2FA) adds a second verification step every time you log in to QuickEstimate. Even if someone obtains your password, they cannot access your account without also passing the second factor—making unauthorised access dramatically harder.

    Setting up 2FA takes less than five minutes and is one of the most effective security measures available. We strongly recommend enabling it on every QuickEstimate account that contains client data or financial records.

    How to Enable 2FA on Your Account

    Work through these steps to activate two-factor authentication. You'll choose your preferred verification method and then confirm it's working before it goes live.

    1

    Open Security Settings

    All account security controls are managed from a single location in your QuickEstimate settings—no hunting through menus required.

    💡 Tip: Bookmark your Security Settings page so you can return quickly if you ever need to update your 2FA method or generate backup codes.
    2

    Choose Your Verification Method

    QuickEstimate supports two 2FA methods. Choose the one that best fits how you work — you can switch between them at any time from Security Settings.

    💬
    SMS Text Message

    Receive a one-time code by text message each time you log in. Easy to set up — requires a mobile number.

    Supported authenticator apps:
    📲 Google Authenticator 🔐 Authy 🛡️ Microsoft Authenticator 🔑 1Password
    💡 We recommend an authenticator app over SMS — it works without mobile signal, isn't vulnerable to SIM-swap attacks, and generates codes faster.
    3

    Set Up Your Authenticator App

    If you chose the authenticator app method, follow these steps to link your app to your QuickEstimate account using a QR code.

    ⚠️ Important: Act quickly when entering the code — each code is only valid for 30 seconds. If it expires, simply wait for the next code to appear in your app.
    4

    Set Up SMS Verification (Alternative)

    If you chose SMS as your verification method, QuickEstimate will send a one-time code to your mobile number each time you log in.

    💡 Tip: Make sure you enter the mobile number you always have access to — ideally your personal phone rather than a work phone that could be reassigned.

    SMS codes expire after 10 minutes. If you don't receive a message within 60 seconds, click Resend Code — check that your number was entered correctly including the country code.

    5

    Save Your Backup Codes

    After enabling 2FA, QuickEstimate generates a set of one-time backup codes. These are your emergency access method if you ever lose your phone or can't receive your normal verification code.

    ⚠️ Do not store backup codes in the same place as your password. If someone gains access to both, 2FA provides no protection. Treat them like a spare key.
    6

    Test Your Login

    Before relying on 2FA day-to-day, confirm that the full login flow works correctly from start to finish.

    💡 Tip: On devices you use regularly, you can tick "Trust this device for 30 days" to skip the 2FA step on that device — while still protecting logins from new or unknown devices.

    2FA is now protecting your account. Every login from an unrecognised device will require your verification code going forward.

    🔒

    What 2FA Protects on Your QuickEstimate Account

    Once enabled, 2FA secures access to all sensitive areas of your account on any unrecognised device:

    Even if your password is compromised in a data breach, 2FA ensures your account remains inaccessible without the second verification step.

    Tips for Staying Secure

    Two-factor authentication is your strongest defence — these additional habits keep your account and client data fully protected.

    🔑

    Use a Strong, Unique Password

    2FA works best alongside a strong password. Use at least 12 characters with a mix of letters, numbers, and symbols — and never reuse it across other sites.

    🛡️

    Store Backup Codes Securely

    Save your backup codes in a password manager like 1Password or Bitwarden — not in a plain text file, email draft, or note that isn't encrypted.

    📲

    Keep Your Auth App Backed Up

    If you use Google Authenticator, enable cloud backup in the app settings. Authy and 1Password back up automatically — so a new phone doesn't lock you out.

    🚪

    Review Trusted Devices Regularly

    Periodically visit Security Settings and revoke trusted device status from old phones, laptops, or devices you no longer use or own.

    👥

    Enable 2FA for All Team Members

    On Business plans, admins can require 2FA across all team accounts. One unsecured team login is all it takes to expose your entire account.

    🔄

    Regenerate Backup Codes After Use

    If you ever use a backup code to access your account, generate a fresh full set immediately from Security Settings so you're never left without a fallback.

    Frequently Asked Questions

    What happens if I lose my phone and can't access my authenticator app?

    Use one of your saved backup codes to log in — each code is a one-time emergency bypass that lets you access your account without your authenticator. Once logged in, immediately go to Security Settings to reconfigure 2FA on your new device. If you have no backup codes, contact QuickEstimate support with account verification details to regain access.

    Can I switch from SMS to an authenticator app after setup?

    Yes. Go to Account Settings → Security → Two-Factor Authentication and click Change Method. You'll be walked through the setup for the new method and your old method will be deactivated once the new one is confirmed. You don't need to disable 2FA first.

    Will I be asked for my 2FA code every single time I log in?

    Only on unrecognised devices. When logging in from a trusted device, you can tick Trust this device for 30 days to skip the 2FA step on that device for the next 30 days. Logging in from a new browser, device, or incognito window will always trigger the 2FA prompt for your security.

    Is 2FA required for all QuickEstimate accounts?

    2FA is optional for individual accounts but strongly recommended. On Business plans, account administrators can enforce mandatory 2FA for all team members from the Team Settings page — any member without 2FA configured will be prompted to set it up on their next login.

    My SMS codes aren't arriving — what should I do?

    First, check that the mobile number saved in Security Settings is correct and includes the right country code. SMS delivery can occasionally be delayed by up to 60 seconds — wait before requesting a resend. If codes consistently fail to arrive, consider switching to an authenticator app which is more reliable and doesn't depend on mobile network coverage.

    How do I disable 2FA if I no longer want it active?

    Go to Account Settings → Security → Two-Factor Authentication and click Disable 2FA. You'll be asked to confirm with your current password and one final 2FA code to prevent unauthorised deactivation. Note: if 2FA is enforced by your account administrator, you will not be able to disable it individually.

    Account Secured — What's Next?

    Your account is now protected with two-factor authentication. Explore more ways to keep your data safe.