Skip to main content

Security, 2FA, SSO & GDPR

Vemcount security — per-user 2FA, recovery codes, session audit; company password policy; per-brand Azure SSO; the GDPR orphaned-user tool; and personal API keys. Internal reference.

V
Written by Vemco Group

Internal reference — super-admin and partner functions. Not for end customers.

User-level security (User Settings > Security)

  • Two-factor authentication — enabled/disabled per user. When active, shows "Show recovery codes" and "Disable".

  • Recovery codes — one-time backup codes if the 2FA device is lost.

  • Browser sessions — audit log of every active login session (browser/user-agent + IP). A trash icon revokes any individual session.

Company-level password policy

Path: Companies > [Company] > Employee Settings > Password Policy. Three sections:

  • Rules — minimum length; require letters / numbers / uppercase / special characters.

  • Expiration — enable expiration, require admin reset of expired passwords, expiration period in days.

  • Extra security — allow users to change their own password; require company-wide 2FA; block passwords found in known data breaches (breach-check).

SSO / OAuth

SSO is configured per white-label brand via the Branding feature-toggle system. The OAuth section has a Microsoft Azure toggle — when enabled, that brand's users can sign in via Azure AD / Entra ID instead of username and password. Accounts are not auto-synced from Azure; each user still exists in Vemcount.

GDPR compliance tool

Path: Companies > [Company] > Location Management > GDPR. Surfaces users with no or inactive locations connected — an orphaned-user cleanup tool. Columns include User, ID, Location, Opening/Active/Closing/Deactivate dates, and Contract Termination. Used to identify and deactivate users whose locations have closed, per data-retention rules.

API key

Path: Avatar > User Settings > API key. Shows the user's personal API key (masked) with a "Generate new key" button. Used for external integrations and data export via the Vemcount REST API.

Did this answer your question?