Security
Account security, sessions, and access controls
Security Settings
Protect your account with strong security settings. Manage authentication, sessions, and access controls.
Password Security
Strong Password Requirements
Your password must include:
- Minimum 12 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character
Changing Password
Tip
Use a password manager to generate and store strong, unique passwords.
Password History
- Cannot reuse last 5 passwords
- Helps prevent password cycling
Two-Factor Authentication (2FA)
Why Use 2FA
Two-factor authentication adds an extra security layer:
- Even if password is compromised, account stays safe
- Required for accessing sensitive features
- Recommended for all users
Setting Up 2FA
Supported Authenticator Apps
- Google Authenticator
- Authy
- 1Password
- Microsoft Authenticator
- Any TOTP-compatible app
Backup Codes
If you lose access to your authenticator:
- Use one of your backup codes
- Each code works once only
- Generate new codes after use
Warning
Store backup codes securely. They're your only recovery option if you lose your authenticator.
Disabling 2FA
- Go to Settings > Security > 2FA
- Click Disable 2FA
- Enter your password and 2FA code
- Confirm disabling
Session Management
Active Sessions
View all logged-in sessions:
- Go to Settings > Security > Sessions
- See list of active sessions with:
- Device type
- Browser
- Location (approximate)
- Last active time
Ending Sessions
Revoke access from a device:
- Find the session in the list
- Click End Session
- That device is immediately logged out
End All Sessions
Log out everywhere:
- Click End All Other Sessions
- Keeps current session active
- All other devices logged out
Tip
Use "End All Sessions" after changing your password or if you suspect unauthorized access.
Login Security
Login Notifications
Get alerted about account access:
- New device login (always on)
- New location login
- Failed login attempts
Login Restrictions
IP Allowlist (Enterprise)
Restrict access to specific IPs:
- Go to Settings > Security > IP Restrictions
- Add allowed IP addresses or ranges
- Block all other access
Time-Based Restrictions
Limit login times:
- Only during business hours
- Specific days of week
- Custom schedules
Account Lockout
After failed login attempts:
| Attempts | Action |
|---|---|
| 5 failed | 5-minute lockout |
| 10 failed | 30-minute lockout |
| 15 failed | 1-hour lockout + email alert |
API Keys
Managing API Keys
For integrations and automation:
- Go to Settings > Security > API Keys
- Click Generate New Key
- Name your key
- Set permissions
- Copy key (shown only once)
Key Permissions
| Permission | Access |
|---|---|
| Read | View data only |
| Write | Create and update |
| Delete | Remove data |
| Admin | Full access |
Revoking Keys
- Find key in the list
- Click Revoke
- Key immediately stops working
Warning
API keys provide direct access to your data. Treat them like passwords.
Privacy Settings
Data Collection
Control what data Cothon collects:
- Usage Analytics - Help improve the product
- Error Reports - Automatic crash reporting
- Feature Usage - Track feature engagement
Data Retention
Set how long data is retained:
| Data Type | Default | Options |
|---|---|---|
| Activity logs | 90 days | 30-365 days |
| Search history | 30 days | 7-90 days |
| Deleted items | 30 days | Immediate-90 days |
Data Export
Download your data:
- Go to Settings > Security > Data Export
- Click Request Export
- Receive download link via email
- Export includes all your data
Data Deletion
Request complete data deletion:
- Go to Settings > Account > Delete Account
- Request deletion
- 30-day grace period
- Permanent deletion after
Security Log
Viewing Events
See all security-related activity:
- Go to Settings > Security > Security Log
- View chronological list of events
- Filter by event type
Event Types
| Event | Description |
|---|---|
| Login | Successful login |
| Failed Login | Incorrect credentials |
| Password Change | Password updated |
| 2FA Change | 2FA enabled/disabled |
| API Key | Key created/revoked |
| Session End | Remote logout |
Exporting Logs
- Click Export in security log
- Choose date range
- Download CSV file
Organizational Security
Admin Controls
Organization admins can:
- Require 2FA for all members
- Set password policies
- Restrict login methods
- Control data sharing
SSO Integration
For enterprise customers:
- SAML 2.0 support
- Google Workspace SSO
- Microsoft Entra ID (Azure AD)
- Okta integration
Contact sales for SSO setup.
Security Recommendations
Essential Steps
- Enable two-factor authentication
- Use a strong, unique password
- Review active sessions regularly
- Enable login notifications
Best Practices
- Don't share your password
- Log out on shared devices
- Review API key permissions
- Check security log periodically
Note
Cothon is SOC 2 Type II certified. Your data is protected by industry-leading security measures.
Next Steps
- Organization Settings - Team security
- Notifications - Security alerts
- Integrations - Secure integrations
Was this page helpful?