# Security Policy — Dedupely Knowledge Base

> Dedupely has designed a range of proactive measures, from enforcing two-factor authentication (2FA) to managing inactive sessions and whitelisting IP addresses.

- URL: https://dedupe.ly/knowledge-base/security
- Section: knowledge-base
- Site index: https://dedupe.ly/llms.txt
- Any page: append `.md` to its URL for this plain-text form

---

## Security Policy

Access to Security Policy settings is restricted strictly to admin-level users.
Enforcing company-wide security policies prevents unauthorized access, and aligns your deduplication project with internal compliance standards.
All security rules apply company-wide to every user in your organization. By default, minimum password length is set to 12 characters, password expiration is set to Never, and 2FA is optional unless enforced by an admin.

### Recommendations for Account Security Enhancement

- **Enforce 2FA for all users:** Implement two-factor authentication (2FA) across your organization to add an extra layer of security to account logins.
- **Enable Password Expiration:** Ensure passwords expire periodically to mitigate the risk of unauthorized access.
- **Keep Password Expiration at 90 days or less:** Set a policy where passwords must be changed every 90 days or less to maintain continuous security.
- **Increase Minimum Password Length to 15:** Require users to create passwords of at least 15 characters to improve password strength.
- **Enable Close Sessions When Inactive:**Automatically log out inactive users to prevent unauthorized access in case of prolonged inactivity.

### Security Policy Configurations

Use these settings to customize your account security, password requirements, and access controls:

### Passwords and Authentication

- Minimum Password Length: Require a minimum password length.
- Passwords Expire After: Set passwords to expire every 30, 60, 90, 180 days, or Never.
- Password Reuse Prevention: Check this box to prevent users from reusing a specified number of past passwords.
- Enforce 2FA: Require two-factor authentication for account logins.

### Inactive Sessions

- Close Sessions When Inactive: Automatically log out users after a specified period of inactivity to prevent unauthorized access on unattended screens.

### IP Whitelist

- Whitelist IPs: Restrict workspace login access to specific static IP addresses.
Related articles:
[Company Settings](https://dedupe.ly/knowledge-base/company-settings),
[Users](https://dedupe.ly/knowledge-base/users), and
[Audit Log](https://dedupe.ly/knowledge-base/audit-log).

### Still stuck?

-
Need help?
[Talk to support](https://dedupe.ly/contact)
-
Questions about plans?
[Book a Zoom with sales](https://meetings.dedupe.ly/meetings/hampus-isaksson/dedupely-zoom-schedule)
-
Reading this with a model?
[Read this page as Markdown](https://dedupe.ly/knowledge-base/security.md)
-
Feeding it the whole site?
[Read llms.txt](https://dedupe.ly/llms.txt)

### Get started for free

20 free trial merges and as much free support as you need to get your duplicates under control.
[Talk to sales](https://meetings.dedupe.ly/meetings/hampus-isaksson/dedupely-zoom-schedule)[Try for free](https://v2.app.dedupe.ly/signup)
[Or sign up with Google](https://v2.app.dedupe.ly/signup/google)
Running CRM cleanup for clients? [See the Partner Program](https://dedupe.ly/become-a-partner)
Skip to content
