User Security

How CheckWorkRights keeps your users data safe, secure and private.

Updated over a week ago

Please contact your CheckWorkRights account manager to enable the following features on your account.

Mobile SMS Two-Factor Authentication

When using CheckWorkRights, you can request your user's login using "Mobile SMS Two-Factor Authentication". This feature creates a higher level of security, adding a second layer of security to your login process. After the initial login process, CheckWorkRights sends users a code via SMS to their mobile to authenticate their request.

Password Policy Controls

We have a strict password creation policy at CheckWorkRights, with a default protocol of eight characters with at least one letter, one number and one special character included. Passwords can be as long or complicated as you like, provided you can remember them easily enough.

If you'd like to enforce an additional layer of security on your users, we offer custom password policy configurations based on your requirements. This can include longer passwords or more varied characters.

Magic Linking

Magic linking, also known as password-less authentication, is a method of allowing users to access their accounts or systems without using traditional usernames and passwords. With Magic Linking enabled on your account, users enter only their email address into CheckWorkRights and are then sent a secure one-time link to log in.

Here's how it works:

  1. User Request: When a user wants to log in, they enter their email address on the login page.

  2. Email with Magic Link: The system then sends an email to the provided email address. This email contains a special link that is valid for 15 minutes.

  3. Clicking the Link: The user opens the email and clicks the magic link. This action confirms their identity and grants them access to their account.

Magic linking is considered a more user-friendly and potentially more secure alternative to traditional username/password combinations because it eliminates the need for users to remember and manage complex passwords.

Additionally, it can enhance security by requiring access to the user's email account to click the link, The link is only valid for 15 minutes, reducing the risk of interception or misuse.

Domain Name User Creation

With Domain Name User Creation, you can restrict the creation of a new user account in CheckWorkRights to a specific domain name, usually the same one that manages your business email.

This prevents misuse of the user creation platform with insecure public email addresses. When combined with the Magic Linking feature above, this ensures that only current HR Team Members have access to CheckWorkRights and your sensitive data. If an HR Team Member leaves the business, their access to the platform is removed with the access to their email address.

Did this answer your question?