CRAnotify Documentation

Account security

The account gives access to the organisation's evidence file: whoever gets in can read reports that are not yet public and produce acts that stay on the record. The security settings are in Account area › My account › Security and concern each user individually.

Password

  • Minimum length 10 characters; changing it requires the current password.
  • It is stored only as a digest with an adaptive algorithm: it is not readable, not even by us.
  • A change leaves a registry row (without the value, of course) and invalidates the other sessions.

Use a password manager and a long passphrase rather than a complicated password you have to remember. If your organisation has single sign-on, prefer that: one credential fewer to manage.

Two-step verification

Based on time-based codes (TOTP) generated by an authenticator app. Three steps to enable: generate the key, capture it in the app, confirm with a six-digit code. On confirmation the recovery codes appear, shown once and downloadable.

Keep the recovery codes outside the application and outside the phone that generates the codes. Each code works once. Without the app and without the codes, getting back in requires identity checks that are not instant.

The code changes every 30 seconds and is accepted with a small clock tolerance. If it is always rejected, the device's time is off: synchronise it.

Active sessions

The list shows open sessions with device and location; the current one is highlighted. Each row can be revoked individually, with immediate effect. Revoke when: you change laptop, you suspect an access that was not yours, or somebody leaves the company.

How the session works

Session cookieNot readable by scripts, sent over HTTPS only in production, with protection against being sent from third-party sites.
ExpirySessions have a limited lifetime; after a period of inactivity you sign in again.
FormsEvery form that changes data carries an anti-forgery token: a page on another site cannot act on your behalf.

Defences that apply to everyone

  • Rate limits on sign-in, password reset and sign-up, to blunt automated attempts.
  • Anti-bot check with Cloudflare Turnstile (invisible CAPTCHA) on the public sign-in and sign-up forms, when configured.
  • Notification of sensitive changes: changing the email address alerts both the old and the new address, so a silent takeover is not possible.
  • Security headers and a restrictive content policy on every application page, which cannot be framed by other sites.
  • Isolation between organisations: every request is resolved against the user's organisation; attachments are reachable only from their own.

If you suspect unauthorised access

  1. Change the password and enable two-step verification if it is off.
  2. Revoke all sessions except the current one.
  3. Rotate or revoke the organisation's API keys.
  4. Export the registry: it will contain the actions performed, with moment and author.
  5. Open a request with support, stating the suspicious time window.

The security of the service

To report a vulnerability in CRAnotify itself: security@cranotify.eu. We accept coordinated disclosure and respond within the times stated in our security.txt. Communications about breaches that concern you follow the path described in Personal data and retention.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu