Account security
The account gives access to the organisation's evidence file: whoever gets in can read reports that are not yet public and produce acts that stay on the record. The security settings are in Account area › My account › Security and concern each user individually.
Password
- Minimum length 10 characters; changing it requires the current password.
- It is stored only as a digest with an adaptive algorithm: it is not readable, not even by us.
- A change leaves a registry row (without the value, of course) and invalidates the other sessions.
Use a password manager and a long passphrase rather than a complicated password you have to remember. If your organisation has single sign-on, prefer that: one credential fewer to manage.
Two-step verification
Based on time-based codes (TOTP) generated by an authenticator app. Three steps to enable: generate the key, capture it in the app, confirm with a six-digit code. On confirmation the recovery codes appear, shown once and downloadable.
Keep the recovery codes outside the application and outside the phone that generates the codes. Each code works once. Without the app and without the codes, getting back in requires identity checks that are not instant.
The code changes every 30 seconds and is accepted with a small clock tolerance. If it is always rejected, the device's time is off: synchronise it.
Active sessions
The list shows open sessions with device and location; the current one is highlighted. Each row can be revoked individually, with immediate effect. Revoke when: you change laptop, you suspect an access that was not yours, or somebody leaves the company.
How the session works
Defences that apply to everyone
- Rate limits on sign-in, password reset and sign-up, to blunt automated attempts.
- Anti-bot check with Cloudflare Turnstile (invisible CAPTCHA) on the public sign-in and sign-up forms, when configured.
- Notification of sensitive changes: changing the email address alerts both the old and the new address, so a silent takeover is not possible.
- Security headers and a restrictive content policy on every application page, which cannot be framed by other sites.
- Isolation between organisations: every request is resolved against the user's organisation; attachments are reachable only from their own.
If you suspect unauthorised access
- Change the password and enable two-step verification if it is off.
- Revoke all sessions except the current one.
- Rotate or revoke the organisation's API keys.
- Export the registry: it will contain the actions performed, with moment and author.
- Open a request with support, stating the suspicious time window.
The security of the service
To report a vulnerability in CRAnotify itself: security@cranotify.eu. We accept coordinated disclosure and respond within the times stated in our security.txt. Communications about breaches that concern you follow the path described in Personal data and retention.