--- title: "Account security (Help Center / Privacy & security / Application)" ai_context: "Use this article for questions about RUMvision account security, authentication, passwords, two-factor authentication (2FA), login protection and recovering or securing user access. It covers password strength, breached credential checks, password hashing, enforcing 2FA, resetting lost 2FA, re-authentication for sensitive actions, login rate limiting, successful and failed login history, suspicious account activity, individual user accounts and organisation responsibilities for access security. Relevant for questions about compromised accounts, password security, brute-force protection, 2FA recovery, login attempts, account takeover concerns, removing user access, roles and permissions, and how account-level protections relate to broader RUMvision platform security." canonical: "https://www.rumvision.com/help-center/privacy-security/application/account-security/" --- Breadcrumbs: [Home](https://www.rumvision.com/?format=md) > [Help Center](https://www.rumvision.com/help-center/?format=md) > [Privacy & security](https://www.rumvision.com/help-center/privacy-security/?format=md) > [Application](https://www.rumvision.com/help-center/privacy-security/application/?format=md) > Account security # How do we protect your account? Your RUMvision account can provide access to performance data, domains, configuration and other information belonging to your organisation. We therefore use several layers of protection around authentication and account access. Some controls are applied automatically by RUMvision, while others can be managed or enforced by you and your organisation. ## How are passwords protected? RUMvision requires passwords to meet a minimum strength threshold and provides password-strength feedback when you create or change a password. We also check whether credentials appear in known public breach datasets. This helps prevent the use of passwords that are already known to have been compromised elsewhere. Passwords are not stored in plain text. They are securely hashed before storage. ## Do you support two-factor authentication? Yes. RUMvision supports two-factor authentication (2FA) to add an additional layer of protection to your account. Depending on your organisation's configuration, 2FA can also be enforced for users with access to a domain. If 2FA is required, users are prompted for their second factor during login after successfully entering their account credentials. ## What happens if I lose access to 2FA? If you lose access to your two-factor authentication method, an authorised user within your organisation may be able to reset your 2FA configuration. Because resetting 2FA can restore access to an account, requests should always be verified carefully. We recommend confirming the user's identity through a separate trusted channel before performing a reset. ## Do sensitive actions require extra verification? Yes. Some security-sensitive actions require you to confirm your identity again by entering your current password, even when you are already logged in. This additional verification helps reduce the risk of someone making important account or security changes from an unattended or compromised session. ## Do you protect against repeated login attempts? Yes. RUMvision uses rate limiting and protections against repeated authentication attempts. Repeated failed login attempts can be throttled to reduce the risk of automated password guessing and similar attacks. ## Can I see previous login attempts? Yes. RUMvision provides recent login history so you can review successful and failed login attempts associated with your account. This can help you identify unexpected activity and investigate whether someone may have tried to access your account. ## What should I do if I suspect unauthorised access? If you suspect that someone else has gained access to your account, you should change your password immediately and contact RUMvision if further investigation is needed. You should also review recent login activity and check whether your two-factor authentication and other account settings are still correct. ## What is my organisation responsible for? Account security is shared between RUMvision and the organisations using the platform. We provide authentication controls and security protections, while you should make sure that: - users have their own individual accounts - passwords are not shared - two-factor authentication is enabled or enforced where appropriate - access is removed when someone no longer needs it - suspicious account activity is investigated promptly Access to specific domains and functionality can also be controlled separately through roles and permissions. [Read about domain and access security](https://www.rumvision.com/help-center/privacy-security/application/domain-security/?format=md) ## How does RUMvision protect the platform itself? Login security is only one part of protecting customer data. RUMvision also applies measures such as encryption, restricted production access, security logging, vulnerability monitoring, backups and incident-response procedures to protect the application and its underlying systems. [Read about platform security](https://www.rumvision.com/help-center/privacy-security/application/platform-security/?format=md)