Security at Besecure

How Besecure protects the front door to every application your organisation runs.

Authentication

  • Two-factor authentication by authenticator app or one-time code
  • Password policy configured per organisation — length, complexity, rotation
  • Automatic account lockout after repeated failed sign-ins
  • Rate limiting on authentication endpoints
  • Forced password change and first-time-login setup flows

Network and location controls

  • Sign-in restricted by IP address
  • Sign-in restricted by geography
  • Clear, non-leaking error messages when access is refused

Visibility and accountability

  • Audit log of sign-ins, sign-outs and profile changes
  • Administrative actions recorded against the administrator who made them
  • Exportable reports for access reviews
  • Dashboards for failed sign-ins and suspicious activity

Least privilege by design

  • Role-based access with granular role permissions
  • Per-application access policies
  • Time-boxed support access instead of shared administrator credentials
  • Shared identities handled explicitly rather than by passing passwords around

Common questions

Does this website handle any credentials?

No. Authentication, organisation creation and the application dashboard all live in the Besecure app on its own subdomain. This marketing site never receives a password.

Which certifications does Besecure hold?

This is being confirmed and will be published here once verified. We would rather show nothing than a badge we cannot evidence.

How do we report a security issue?

Contact us and mark it as a security report. Our disclosure contact is also published at /.well-known/security.txt.

Security questions before you commit?

Send them over. We would rather answer them properly than have you guess.