Sign in & accounts

The SuperFile family is several products with one idea about identity: you prove you hold a mailbox (or a passkey or a device you already trust), and from then on the file, the name or the tenant knows who you are. This page lists every sign-in path, product by product, and what happens to your session afterwards.

#superfile.com — your SuperFile Account

Your SuperFile Account is created the first time you reserve a name and confirm the 6-digit code we email you; there is no separate registration form. Sign in afterwards at superfile.com/signin.

PathHow it worksGood for
Email linkEnter your address; we send a sign-in link. It is valid for 7 days and must be opened on the device you want signed in.Everyone, every device
Sign in with your phoneOn a desktop, the sign-in page shows a QR code. Open the camera on a phone that is already signed in, scan, tap Approve. The desktop signs in within seconds; the code expires after 10 minutes and works once.A new laptop, a shared machine
PasskeyAfter your first sign-in, add a passkey in Settings → Sign-in & Security. From then on, sign in with Face ID, Touch ID, Windows Hello or a security key.The fastest, phishing-resistant path

A few details worth knowing:

  • Old links to /login still work; they redirect to /signin.
  • Signed-in visitors who open the sign-in page are sent straight to the dashboard.
  • Sessions last 7 days from the last sign-in. Settings → Sign-in & Security → Where you're signed in lists every device with its browser, approximate location and last activity; sign any of them out, or sign out all other devices at once. Session tokens never reach the page, and IP addresses are shown masked.
  • Reserving a name from a signed-in dashboard skips the code step — the mailbox was already proven at sign-in.

#beta.supersecure.com — SuperSecure

SuperSecure has its own accounts: an account is an account, the way a Gmail address is. The same person can hold several — say a personal one and one for their company — with separate files, sessions and billing.

  • Sign up / sign in with a one-time code. Enter your email; we send a 6-digit code; type it in. There is no password to remember or leak.
  • Sign in with sup. If you already hold a sup account, use it as your identity provider (OpenID Connect). Your SuperSecure account is linked to it on first use.
  • One mailbox, several accounts. When a mailbox belongs to more than one account, sign-in shows a chooser; pending invitations from an organisation appear there as Join <org> and provision your seat when you pick them.
  • Switch or sign out. The account rail lists every account signed in on this browser. Sign out of one, or of all of them; signing out of one hops you to the next signed-in account. Signing out clears the offline cache and every draft on that device — a per-device drafts vault holds files you dropped before signing in, and those are migrated into your vault automatically when you do.
  • Invitation gate. During the beta some entry points ask for an invite code and an I agree on the beta terms before the sign-up form appears.

Drafts and preferences are stored per device; a second tab or browser starts from what the server knows, not from the first tab's unsaved state.

#superdrm.com — the SuperDRM portal

The portal at superdrm.com/portal is where a company runs its DRM tenant.

  1. Sign up with company name, email and password. The tenant is created at once on the developer plan in pending status, with its API key and token secret shown once.
  2. Verify your email from the link we send. That activates the tenant and signs you in. Licence endpoints refuse until this step is done.
  3. Sign in afterwards with email and password, or with Sign in with sup. Sessions are 30-day, secure, HTTP-only cookies. A password reset revokes every other session. Sign-in, sign-up and reset are rate-limited per address.
  4. Team: owners invite admins and members by email; the invitation link accepts into the tenant. The account switcher lists every tenant your sup identity can reach.

Everything the portal does is a plain JSON API under /v1/portal/*; see Portal & console.

#sup.com — Sup

Sup is messaging, calls and mail built on top of your files, and it doubles as an identity provider — Sign in with sup on superdrm.com and beta.supersecure.com uses it. Sup accounts sign in with a password and, where added, a passkey; a workspace can bind a business domain so colleagues sign in with their work address. Sessions are shared across sup.com sub-domains.

#Security notes that apply everywhere

  • We never ask for your password by email, and superfile.com and beta.supersecure.com have no passwords at all: a link or a code that arrives unexpectedly should be ignored.
  • Every sign-in path records the device, approximate location and time so you can audit it later from your settings.
  • Personal data handling is described in the Privacy Policy and the Data & Subprocessors page; aggregate figures are published in the Transparency Report.

Updated September 2026