Security is essential for protecting your business data. This guide covers the security features available in EvoDax and how to configure them.
Security Overview
EvoDax provides:
- Encrypted data transmission (TLS/SSL)
- Secure data storage
- Role-based access control
- Session management
- Audit logging
Password Policy
Requirements
Default password requirements:
- Minimum 8 characters
- At least one uppercase letter
- At least one number
- At least one special character
Configuring Policy (Enterprise)
- Go to Settings > Security
- Under Password Policy:
- Set minimum length
- Require complexity
- Password expiry (e.g., 90 days)
- Prevent reuse
Session Management
Session Timeout
Auto-logout after inactivity:
- Go to Settings > Security
- Set timeout duration:
- 15 minutes (high security)
- 1 hour (standard)
- 8 hours (convenience)
- Save
Active Sessions
View and manage your sessions:
- Go to your profile
- Click Security
- See active sessions
- Click Sign out to end a session
- Sign out all for security concerns
Two-Factor Authentication (Enterprise)
Add extra login security with 2FA.
Enabling 2FA
- Go to profile > Security
- Click Enable 2FA
- Choose method:
- Authenticator app (Google, Authy)
- SMS (phone number required)
- Scan QR code or enter code
- Verify with test code
- Save backup codes
Company-Wide 2FA
Admins can require 2FA for all users:
- Go to Settings > Security
- Enable Require 2FA
- Set grace period for setup
- Users prompted on next login
Access Control
IP Restrictions (Enterprise)
Limit access to specific IPs:
- Go to Settings > Security
- Under IP Allowlist
- Add allowed IP addresses/ranges
- Enable restriction
Useful for office-only access.
API Key Management
For API integrations:
- Go to Settings > API
- View existing API keys
- Create new keys
- Set permissions per key
- Rotate keys regularly
Audit Logging
Track important events:
- User logins/logouts
- Settings changes
- Data access
- Permission changes
Viewing Audit Logs
- Go to Settings > Audit Log
- Filter by:
- User
- Action type
- Date range
- Export for compliance
Audit Retention
Logs retained based on plan:
- Starter: 30 days
- Professional: 90 days
- Enterprise: 1 year+
Data Privacy
Data Export
Export your data:
- Go to Settings > Privacy
- Click Request Data Export
- Receive download link
Data Deletion
Request account deletion:
- Go to Settings > Privacy
- Click Delete Account
- Confirm (irreversible)
- 30-day retention before permanent deletion
Security Notifications
Get alerted to security events:
- New device login
- Failed login attempts
- Password changes
- 2FA changes
Enable in Settings > Notifications > Security.
Best Practices
- Use strong passwords - Unique for each service
- Enable 2FA - Extra protection
- Review access - Audit users regularly
- Monitor audit logs - Spot suspicious activity
- Keep contacts updated - For security alerts
- Train your team - Security awareness
Security Questions?
Contact us:
- security@evodax.com
- Report vulnerabilities responsibly
- We take security seriously