Security & Compliance

Password & Session Policies

Enforce password complexity, expiry, re-use prevention, and configurable session timeouts — with forced re-authentication for high-risk actions.

Get Started Free

Password & Session Policies give your security team centralised control over the authentication hygiene standards applied to every platform user. Define minimum password complexity, enforce regular changes, prevent re-use of recent passwords, set session timeouts appropriate to each role's risk profile, and require fresh authentication before any high-stakes action — all from the admin panel, applied consistently across the entire user base.

Complexity & length rules Expiry & re-use prevention Per-role session timeouts Forced re-auth on high-risk Account lockout on failures Bulk policy enforcement
What's included

Everything you need, nothing you don't

Password Complexity Rules

Enforce minimum length, uppercase, lowercase, number, and special character requirements — configurable per role so admin accounts have stricter requirements than basic teller accounts.

Password Expiry Intervals

Set a maximum password age per role. Users are notified 7 days before expiry and blocked at login on expiry until they change their password.

Password Re-Use Prevention

Prevent users from reusing any of their last N passwords — configurable from 5 to 24 previous passwords — eliminating password cycling as a security bypass.

Per-Role Session Timeouts

Set inactivity timeout durations per role — short timeouts for branch tellers who share terminals, longer for office-based analysts who work uninterrupted sessions.

Absolute Session Limits

Set a maximum session duration regardless of activity — ensuring a session opened at 9am cannot still be active at midnight, even if the user has been continuously active.

Failed Login Lockout

Automatically lock accounts after a configurable number of consecutive failed login attempts. Locked accounts require admin unlock or a self-service unlock via a verified email or SMS.

Re-Authentication for High-Risk Actions

Force users to re-enter their credentials (and 2FA if enrolled) before executing high-risk actions — bulk payments, write-off approvals, role assignments — regardless of active session state.

Bulk Policy Enforcement

Apply a new password policy to all users simultaneously — with a grace period during which users are notified to update their passwords before enforcement kicks in.

Who uses this module

Built for your team

IT & Security Teams

Set and maintain password and session standards that protect the platform against credential-based attacks — without managing them on a per-user basis.

Compliance Officers

Demonstrate that your organisation enforces password standards consistent with your information security policy and any applicable regulatory requirements.

HR & Operations Teams

Benefit from automatic account management — new starters prompted to set a compliant password, leavers' accounts automatically expiring without manual intervention.

Ready to activate Password & Session Policies?

Sign up free and configure Password & Session Policies in minutes — or book a demo and we'll walk you through it live.

Get Started Free