Security on your side: the habits we can't do for you
The platform can encrypt, log, throttle and isolate. It cannot stop someone signing in with a password that is also their Facebook password, from a link in a message, on a tablet that is never locked. That part is yours, and it is short.
On this page
Settings you can make todayHabits to teachHabits for the ownerWhat an attack on a small landlord actually looks likeSettings you can make today
Require two-factor for every staff account in Settings › Security. Set an auto-lock on the reception tablet and any shared phone. Check roles in People › Staff: anyone who is an admin and does not need to be, make a manager.
Habits to teach
One account per human, always. Type the address — we never email a sign-in link; a message asking you to sign in is not from us. Lock the screen when you walk away. Use a password manager, even the one in the phone.
Habits for the owner
Deactivate on the day someone leaves. Read the audit log monthly, filtered to sign-ins and lockouts, looking for what you do not recognise. Keep your own export once a month somewhere of your own.
What an attack on a small landlord actually looks like
Not a hacker in a hoodie. A tenant's relative who knows the reception tablet is never locked. A former cleaner whose account was never deactivated. An owner whose email password leaked from a shopping site and was the same one used here. Every one of those is stopped by a habit on this page and by none of the encryption on the others.
Related
Describes the platform as it is today. Something out of date? Tell us. · help 0.12.3