Sensational Security
Following on from our regular security and penetration testing, we're using this release as an opportunity to make several minor changes in line with the recommendations we received during the recent tests;
- Improved Security of Passwords sent via the API
- Added additional security to our web config headers
- Improved Rate Limiting for email and SMS sent via the API
- Reduced automated session timeouts on the Portal
On this last point, there will also be a new configuration setting available in Admin > Security Policy > Portal Policy, where you can control the length of the automated session timeout: |