Security Settings
Configure authentication, access controls, and compliance
Security Settings
Protect your organization with robust security settings.
Authentication
Password Policy
Configure at Settings → Security → Authentication:
- Minimum Length - 8-32 characters (default: 12)
- Require Uppercase - At least one capital letter
- Require Lowercase - At least one lowercase letter
- Require Numbers - At least one digit
- Require Symbols - At least one special character
- Password History - Prevent reuse of last N passwords (default: 5)
- Max Age - Force rotation after N days (0 = never)
- Lockout Threshold - Failed attempts before lockout (default: 5)
- Lockout Duration - Minutes locked after threshold (default: 15)
Two-Factor Authentication (2FA)
- Optional - Users can enable individually
- Required for Admins - Enforced for Admin+ roles
- Required for All - Enforced organization-wide
- Methods - Authenticator app, SMS, Email
Single Sign-On (SSO) (Enterprise)
Configure SAML/OIDC:
- Identity Provider - Okta, Azure AD, Google Workspace, custom
- Attribute Mapping - Email, name, roles, groups
- Just-in-Time Provisioning - Auto-create users on first login
- SCIM Provisioning - Sync users/groups from IdP
Access Control
IP Allowlist
Restrict access to approved networks:
- Add CIDR ranges (e.g.,
192.168.1.0/24) - Separate lists for admin panel vs. user portal
- Emergency override for owners
Session Management
- Idle Timeout - Auto-logout after inactivity (15 min - 8 hours)
- Absolute Timeout - Force re-login after max session (1-30 days)
- Concurrent Sessions - Limit simultaneous logins per user
- Device Management - View and revoke active sessions
Device Trust (Enterprise)
- Require Managed Devices - Only approved devices
- Certificate-Based Auth - Client certificates
- Device Health Checks - OS version, encryption, etc.
Compliance
Data Protection
- GDPR - EU data subject rights, DPA, transfer mechanisms
- HIPAA - PHI handling, BAA, audit controls
- POPIA - South Africa data protection
- NDPR - Nigeria data protection regulation
Audit Logging
All security events logged:
- Login/logout (success/failed)
- Permission changes
- Data exports
- Configuration changes
- API access
Retention: 1 year standard, 7 years enterprise.
Certifications
- SOC 2 Type II (annual)
- ISO 27001 (certified)
- PCI DSS Level 1 (for payments module)