Every sign-in needs your password and a second factor:
Five wrong codes lock that sign-in attempt; wrong passwords are rate limited per account and per network.
You get 10 when you set up the authenticator. Generate a new set in Settings → Security (the old ones stop working). If you lose your phone and your codes, contact support: staff can remove your authenticator after verifying your identity, and you set up a new one at the next sign-in. Staff can never read your codes or turn two-factor off.
Settings → Security lists every device signed in to your account; sign any of them out. Sessions end after a period of inactivity, and a suspicious reuse of an old session token ends the session immediately.
RootBounty uses only the cookies it needs to keep you signed in, plus optional error reporting you can accept or decline. See the cookie policy.