Good to know: SecurynAI's free tier is a fully deterministic security plugin on its own — firewall, scanning, and hardening all work with no setup. Plain-English AI explanations require your own OpenAI or Anthropic API key (typically ~$0.10–$0.30/month); without one, you still get clear fallback explanations, just not full AI narratives.

It's not really about "location"

The first thing worth clearing up: this isn't GPS or physical geography. SecurynAI doesn't know where you're physically sitting, and it's not trying to guess. What it's actually looking at is what we call a new origin — a combination of a new IP address and a new device signature that hasn't logged into this account before.

That distinction matters because IP-based geolocation is often wrong or misleading — a VPN, a mobile carrier reassigning IPs, or traveling can all make a login look like it came from somewhere unexpected when nothing is actually wrong. A "new origin" check is more reliable because it's not trying to interpret geography at all — it's just noticing that this combination hasn't been seen before.

What actually gets checked

A login gets scored on a few independent signals:

  • New IP address — this specific address hasn't logged into this account before
  • New device — the browser/device fingerprint doesn't match previous logins
  • Off-hours activity — the login happened in the middle of the night relative to typical server time
  • A failed-login burst just before success — several failed attempts followed by a successful one, which can indicate credential guessing that eventually landed

These combine into a risk score. Low scores mean nothing gets flagged. Medium and above surface a finding you can review. High and critical are treated seriously enough to trigger deeper automated review.

Is this actually bad?

It depends entirely on whether the activity was you. A few honest scenarios that trigger this and are completely fine:

  • You logged in from a new laptop or a fresh browser profile
  • You're using a VPN or traveling
  • You logged in from your phone's mobile network for the first time
  • A teammate logged in for the first time from their own device

And a few that mean you should act immediately:

  • You don't recognize the login at all
  • It happened at a time you know you weren't at your computer
  • It came right after a string of failed attempts you didn't make

What to do

  • Ask "was this me or someone I gave access to?" first. Most of these alerts resolve immediately once you remember the new device or location.
  • If you don't recognize it, don't wait. Revoke the session immediately and reset the password for that account.
  • Check what the account did after logging in. A risky login followed by role changes, plugin installs, or file edits is a much stronger signal of compromise than the login alone.
  • Turn on two-factor authentication if it isn't already on for every admin account.

The bigger point

A single flagged login, on its own, is usually not proof of a breach — it's a prompt to double-check. What actually matters is whether it lines up with other unexplained activity. Treat it as a question worth answering quickly, not an emergency by itself, unless you genuinely don't recognize the access at all.

Get every login reviewed and explained automatically.

Install free