June 2026 · Passkeys, backup codes, and a built-in Help center
Released June 2, 2026
A focused release on sign-in security, with a built-in Help center so you can find answers without leaving the app.
Sign-in & security
- Passkeys & hardware security keys. FIDO2 / WebAuthn support for YubiKey, Titan, Touch ID, Face ID, and Windows Hello. Register multiple per account. New registrations save as discoverable passkeys on supporting platforms and sync across devices via iCloud Keychain, Google Password Manager, or 1Password.
- One-time backup codes. Ten single-use codes per account, shown once and downloadable. Each works once at the MFA step in place of TOTP or a passkey. Regenerating immediately invalidates the previous set.
- Self-service recovery key regeneration. Generate a new recovery key from Account settings — the old one stops working instantly. Your password and existing data are untouched.
- Flexible 2FA gate for staff. Either TOTP or a passkey satisfies the forced-MFA requirement for staff and admin accounts.
Sharing & documents
- Link-only document share. Send a file to someone without a Postrider account. Optional password, expiry date, and download limit; revoke from the Documents page at any time.
- Multi-file upload. Select or drag in several files at once.
- Drag-and-drop folder organization. Move documents between folders by dragging. Rename folders inline by clicking the name.
Inbox
- Threaded conversations. Replies are grouped into a single row per thread, with an unread badge counting new messages in that thread.
- Desktop notifications. Opt in from Account settings to get a browser alert when a new secure message arrives. The alert never contains message content.
For organizations
- Storage usage at a glance. The Documents page shows team quota usage as a bar; the Companies admin page surfaces per-org usage alongside seat counts.
- Trial indicator on the Companies admin list, with days remaining.
- Suspend or fully delete users. Suspend instantly blocks sign-in while preserving data (reversible). Delete is a full purge for abuse cases, with a confirmation dialog (not reversible).
- Pending-signup management. Multi-select abandoned signups to purge; per-row resend-invite. Reactivate no longer appears on pending accounts.
- Per-user invite rate limit stops a compromised admin account from being weaponized to spam your users.
- Verified org audit isolation. Org admins see audit entries for their own org only — no cross-tenant bleed, no global system events.
Anti-spam
- hCaptcha + honeypot on the public signup form to filter bots before any email goes out.
- Stale-signup purge job sweeps abandoned pending accounts on a schedule.
Help center
- In-app Help — a new sidebar link opens deep-linkable articles covering signing in, 2FA setup, backup codes, recovery keys, sending messages, documents and folders, share-by-link, account settings, privacy and encryption, and troubleshooting.