Invoicing is live — raise an invoice and get paid into your own merchant account.Start free

How to secure the account you invoice from

An invoice is a payment instruction from a sender your customer already trusts, which is what makes an invoicing login worth stealing. Here is what to turn on, and why the order matters.

Quantum Solutions ·


Most advice about account security is written as though the thing being protected is your data. For an invoicing account it isn't. Your invoices are not especially interesting to anybody else. What is interesting is that you can send one.

An invoice is a payment instruction that arrives from a sender your customer already trusts. It matches the invoices they have had from you before, because it comes from the same place those did. Nothing about it looks wrong, because nothing about it is wrong — except who asked for it.

That is the whole threat model, and it changes what "securing your account" means. You are not protecting a filing cabinet. You are protecting your customers' willingness to pay anything that has your name on it.

Start with the way in, not the password

The advice everybody gives is to use a strong password. It is not wrong, but it protects against the wrong attack. Nobody guesses their way into an invoicing account. They get in with a password the owner reused somewhere that leaked, or one they typed into a page that looked like the real sign-in.

A strong password does nothing about either. A password that does not exist as a typeable secret does something about both.

Add a passkey. A passkey is a key your device holds and your browser proves you have — it is bound to the site it was created for, so a lookalike page cannot ask for it and get anything usable. There is nothing to reuse, nothing to leak in someone else's breach, and nothing to type into the wrong window. In Quantum Solutions you add one from Security → How you sign in, and once it is there you can sign in with it instead of your password.

Or connect a Google account, if that account is itself well protected. This moves the problem rather than solving it — your invoicing account becomes exactly as safe as the Google account behind it — which is fine if that one has two-step verification on it, and not fine if it doesn't.

Then add a second step to the password you still have. An authenticator app generates a code from your phone. It is the difference between a leaked password being a break-in and a leaked password being a nuisance.

Then check the part nobody checks: can you still get in?

This is the failure that actually happens to small businesses, and it has nothing to do with attackers.

You sign up with Google because it is quick. Months later you tidy up your connected accounts, or you leave the organisation whose Google Workspace issued that address, or the account is closed. There is no password on the invoicing account, because you never set one. There is nothing to reset, because a reset email goes to an address you can no longer read.

The account still exists. Your invoices still exist. You cannot reach any of it.

Before you disconnect anything, make sure at least one other way in exists — a password or a passkey. In Quantum Solutions the product will not let you remove your last one: the Disconnect button is disabled and tells you why, rather than letting you strand yourself and finding out weeks later.

Treat "change how I sign in" as its own decision

There is a category of action that is different from everything else you do in an invoicing account. Sending an invoice, editing a customer, exporting a report — if somebody does one of those with your session, you can see it afterwards and undo most of it.

Changing your credentials is not like that. Adding a passkey, removing one, turning off two-step verification, connecting or disconnecting a social login — each of those changes who can be you tomorrow. They are the actions an attacker performs first, precisely because they outlive the session that performed them.

So they deserve a different bar. Quantum Solutions asks you to confirm it is you before any of them, even though you are already signed in — because the thing being defended against is someone using a session that is already open, whether that is a stolen one or your own laptop left unlocked in a co-working space. Being signed in is not evidence that you are the person sitting there now.

If that ever feels like friction, it is worth remembering it is friction the person who wants your customers' payments has to get through too.

A note on the sign-in you cannot re-check

If your only way in is a social login, there is a limit worth knowing about. When we need you to prove it is you again, we cannot ask Google to actually re-check — a provider with a live session will generally just say "yes, still them" without asking anything. Passing that answer off as proof would be theatre.

So an account with nothing but a social login is asked to add a passkey first, and that passkey becomes the thing that answers. It reads like an extra step. It is the difference between a check and a formality.

The short version

  1. Add a passkey. It is the single highest-value thing on this list.
  2. Keep a second way in, always. Never let one credential be the only one.
  3. Put a second step on any password that still works.
  4. Expect to be asked to confirm yourself when you change how you sign in, and be suspicious of any product that doesn't ask.

None of this is a paid tier in Quantum Solutions — it is on every plan, including the free one, because an account you cannot get back into is not a smaller problem for a smaller business.

Related reading

Send your first invoice today

Create an account, connect your gateway and invoice a customer — all in one sitting. The free plan covers real invoicing for a small team.