Security
Security at Dukaanix
Last updated: July 2, 2026
Protecting your account and your business data is a priority for us. Below are the additional security features built into the Dukaanix platform to keep your account safe from unauthorised access and abuse.
Brute-force & abuse protection
- ✅Limit of 5 login attempts per account before temporary lockout.
- ✅Limit of 10 login attempts per IP address every 15 minutes.
- ✅CAPTCHA challenge after 3 failed login attempts.
- ✅Rate limiting on all authentication endpoints to prevent abuse.
Credential security
- ✅Strong password policy — minimum 10 characters with uppercase, lowercase, a number, and a special character.
- ✅Passwords hashed using bcrypt with a cost factor of 12 or higher.
Account & login verification
- ✅Email verification required before your first login.
- ✅Two-Factor Authentication (TOTP or email OTP) — mandatory for administrators, optional for users.
Session & device management
- ✅Automatic session timeout after 30 minutes of inactivity.
- ✅Option to remember trusted devices for 30 days.
- ✅Login history recorded with IP address, browser, device, and time.
- ✅Notifications when a login is detected from a new device.
Auditing & monitoring
- ✅Audit logs stored for security-relevant events.
Questions about security?
If you have a security concern or want to report a vulnerability, email us at security@dukaanix.com.
← Back to home