Authentication & Security Policies

INDPayroll follows stringent security practices to protect sensitive payroll data.

A. Password Security

  • Enforce strong password requirements (uppercase, lowercase, numbers, symbols)
  • Automatic password expiration cycles
  • Prevent reusing the last 3–5 passwords

B. Two-Factor Authentication (2FA)

Admins can enable 2FA for enhanced protection. Methods include:

  • Email OTP
  • SMS OTP
  • Authenticator App (if enabled)

C. Session Management

  • Automatic session timeout after inactivity
  • Browser/device session limit per user
  • Real-time session logs for monitoring unusual access

D. IP & Device Restrictions (Optional Feature)

To enhance security, administrators can restrict system access based on:

  • Whitelisted IPs (office network only)
  • Registered devices or browsers