⌘K
Authentication & Security Policies
INDPayroll follows stringent security practices to protect sensitive payroll data.
A. Password Security
- Enforce strong password requirements (uppercase, lowercase, numbers, symbols)
- Automatic password expiration cycles
- Prevent reusing the last 3–5 passwords
B. Two-Factor Authentication (2FA)
Admins can enable 2FA for enhanced protection. Methods include:
- Email OTP
- SMS OTP
- Authenticator App (if enabled)
C. Session Management
- Automatic session timeout after inactivity
- Browser/device session limit per user
- Real-time session logs for monitoring unusual access
D. IP & Device Restrictions (Optional Feature)
To enhance security, administrators can restrict system access based on:
- Whitelisted IPs (office network only)
- Registered devices or browsers