Skip to content

Security Settings

NEURO provides comprehensive security controls to protect your organization’s data and ensure compliance with security requirements.

Configure password requirements:

SettingOptions
Minimum length8-32 characters
Require uppercaseYes/No
Require lowercaseYes/No
Require numbersYes/No
Require special charsYes/No
Password historyPrevent last N passwords
Maximum ageDays before expiration
  1. Go to SettingsSecurity
  2. Navigate to Password Policy
  3. Set requirements
  4. Save changes

New passwords must meet policy immediately.

MFA can be:

  • Optional (user choice)
  • Required for all users
  • Required for admins only
MethodSecurityConvenience
Authenticator AppHighMedium
Hardware KeyHighestLower
  1. Go to SecurityMFA Settings
  2. Select enforcement level
  3. Set grace period for setup
  4. Save

Users without MFA have grace period to configure.

Configure auto-logout:

  • Timeout period: 30 min - 24 hours
  • Activity-based: Reset on activity
  • Absolute: Fixed session length

Control multiple logins:

  • Allow unlimited
  • Limit to N sessions
  • Single session only

Admins can:

  • View active sessions per user
  • Terminate specific sessions
  • Force logout all users

Restrict access by IP address:

  1. Go to SecurityIP Allowlist
  2. Enable IP allowlisting
  3. Add allowed IP ranges:
    192.168.1.0/24
    10.0.0.0/8
    203.0.113.50
  4. Test with current IP
  5. Enable enforcement

Block access from specific regions:

  • Select blocked countries
  • Or allow specific countries only

Secure API access:

  • Token expiration settings
  • IP restrictions for API
  • Rate limiting configuration

NEURO encrypts data:

Data TypeEncryption
Data at restAES-256
Data in transitTLS 1.3
BackupsAES-256
File uploadsAES-256

Mark data sensitivity:

  • Public
  • Internal
  • Confidential
  • Restricted

Control data exports:

  • Enable/disable bulk export
  • Require admin approval
  • Audit all exports

All security events are logged:

Event CategoryExamples
AuthenticationLogin, logout, MFA
AuthorizationPermission changes
Data AccessViews, exports
ConfigurationSettings changes
  1. Go to SecurityAudit Logs
  2. Filter by:
    • Date range
    • User
    • Event type
    • Resource
  3. Export for compliance

Configure retention:

  • Minimum: 90 days
  • Recommended: 1 year
  • Maximum: 7 years

View security metrics:

  • Failed login attempts
  • MFA adoption rate
  • Session statistics
  • Suspicious activity

Configure security alerts:

  • Multiple failed logins
  • Login from new location
  • Admin action performed
  • Export initiated

When suspicious activity detected:

  1. Alert sent to admins
  2. Option to lock account
  3. Force password reset
  4. Session termination

NEURO supports compliance with:

  • SOC 2 Type II
  • GDPR
  • HIPAA (with BAA)
  • ISO 27001

Export compliance evidence:

  • User access reports
  • Authentication logs
  • Configuration snapshots
  • Data handling records
SettingRecommendation
MFARequired for all
Session timeout2 hours
Password length12+ characters
Password expiry90 days
Failed login lockout5 attempts

Perform periodically:

  • User access review (quarterly)
  • Admin account audit (monthly)
  • Security settings review (quarterly)
  • Audit log review (weekly)

Initial setup:

  • Enable MFA requirement
  • Configure password policy
  • Set session timeouts
  • Enable audit logging
  • Configure alerts
  • Review IP restrictions

Next: Learn about Report Templates