Security
Two-factor authentication, session review, and what happens after too many failed logins.
Two-factor authentication
Settings, then Security. Surf supports authenticator apps using standard time-based codes. Set it up once, keep the recovery information somewhere that is not the phone with the authenticator on it.
Sessions and devices
Active sessions are listed and can be ended individually. Ending a session on a device also removes that device's ability to read new encrypted messages.
Passwords
Passwords are 8 to 128 characters. After five failed attempts, logins are rate limited for fifteen minutes, which is a defence against someone else guessing rather than a punishment for you forgetting.
Changing your email
Changing your email address requires your password, and there is a 24-hour cooldown before it can be changed again.