Appendix A: Security and Privacy

Appendix A: Security and Privacy

You can view and update your security and privacy settings from Security Settings in the top-right menu:

Each of the settings is explained in detail below:

Data Retention

The NoahFace platform automatically deletes Events older than the configured retention period (which is 3 months by default).

Biometric Destruction

The NoahFace platform automatically deletes biometrics either:

  • Immediately. At the same time the associated user is deleted.
  • After Retention. A period of time after the associated user is deleted.

The default setting of Immediately helps you to comply with the widest range of privacy and biometric regulations around the world.

Communication

The NoahFace platform sends registration details (eg: passcodes) and one-time-use codes using the configured communication preference. The options are:

  • Email Only.
  • SMS Only*. Unavailable for NZ based mobile numbers
  • Prefer Email. Use email if an email address is available, otherwise use SMS.
  • Prefer SMS. Not available for NZ based mobile numbers

The default setting of Email Only helps you comply with the widest range of privacy regulations around the world.

Minimum Password Length

You can enforce a minimum password length based on your organisation’s security policy. Users with passwords shorter than the configured minimum length will be required to change their password when they next login.

Password Complexity

You can enforce a minimum level of password complexity (ie: require the use of mixed case, numeric, and special characters) based on organisation’s security policy. Users with passwords that do not meet the configured complexity will be required to change their password when they next login.

Password Expiry Period

You can enforce a password expiry period based on your organisation’s security policy. Users with passwords older than the configured expiry period will be required to change their password when they next login.

Two Factor Authentication

You can enforce two factor authentication for all Dashboard logins based on your organisation’s security policy. When two factor authentication is required, users attempting to login to the Dashboard are sent a six digit code (via the configured Communication method). They need to enter this code to complete their login.

You can configure the frequency of requiring two factor authentication, with the options of:

  • Quarterly.
  • Monthly.
  • Weekly.
  • Always.

Note: two factor authentication is only available to organisations on Enterprise plans.