> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.swellsystem.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Security Settings

# Security Settings

Configure security features to protect your account and data.

## Password Management

### Change Password

Update your password:

1. Go to **Settings** → **Security**
2. Click **"Change Password"**
3. **Enter Current**: Current password
4. **Enter New**: New password
5. **Confirm New**: Re-enter new password
6. **Save**: Password updated

### Password Requirements

**Minimum:**
- 8 characters (recommended: 12+)
- Mix of characters recommended
- Cannot reuse recent passwords

**Best Practices:**
- Use unique password
- Mix uppercase, lowercase, numbers, symbols
- Don't reuse passwords
- Change regularly

## Two-Factor Authentication (2FA)

### Enable 2FA

Add extra security layer:

1. Go to **Settings** → **Security**
2. Enable **"Two-Factor Authentication"**
3. **Scan QR Code**: Use authenticator app
4. **Enter Code**: Verify with code
5. **Save Backup Codes**: Store securely
6. **2FA Enabled**: Extra security active

### Authenticator Apps

Use apps like:
- Google Authenticator
- Authy
- Microsoft Authenticator
- 1Password
- LastPass

### Backup Codes

**Important**: Save backup codes:
- Store in secure location
- Use if you lose access to authenticator
- Can disable 2FA if needed
- Generate new codes if used

## Session Management

### Active Sessions

View logged-in devices:

1. Go to **Settings** → **Security** → **Active Sessions**
2. **See All Sessions**: All logged-in devices
3. **Device Info**: Browser, location, last activity
4. **Logout Device**: Sign out specific device
5. **Logout All**: Sign out from all devices

### Session Timeout

Automatic logout:
- **Inactivity**: Logout after inactivity period
- **Security**: Prevents unauthorized access
- **Configurable**: May be configurable per plan

## Security Best Practices

1. **Strong Password**: Use strong, unique password
2. **Enable 2FA**: Add two-factor authentication
3. **Regular Updates**: Change password regularly
4. **Monitor Sessions**: Review active sessions
5. **Logout When Done**: Sign out when finished
6. **Secure Devices**: Use secure devices only
7. **Report Suspicious**: Report suspicious activity

## Troubleshooting

**Can't change password?**
- Verify current password is correct
- Check new password meets requirements
- Ensure passwords match
- Try refreshing page

**2FA not working?**
- Verify authenticator app time is correct
- Check code is entered correctly
- Use backup code if needed
- Contact support to disable 2FA

**Suspicious activity?**
- Change password immediately
- Logout all sessions
- Enable 2FA if not enabled
- Contact support

For more help, see [Common Issues](https://help.swellsystem.com/en/article/common-issues-solutions-1i0z5vq/).

## Next Steps

- [Account Settings](https://help.swellsystem.com/en/article/account-settings-l0236a/) - Manage profile
- [Team Management](https://help.swellsystem.com/en/article/team-management-1x692m2/) - Manage team
- [Billing & Subscriptions](https://help.swellsystem.com/en/article/billing-subscriptions-1qwalvv/) - Subscription management
