Security & Audits

Password policy and account security

Requirements for secure passwords and what to do when suspicious activity is detected.

Last updated: February 15, 2026

Password requirements

VollSign requires passwords with at least 8 characters, including 1 uppercase letter, 1 lowercase letter, 1 number, and 1 special character. Passwords are hashed with bcrypt (cost factor 12) and never stored in plain text.

Account lockout on suspicious activity

After 5 consecutive failed login attempts, the account is automatically locked for 15 minutes. You will receive an email notification. If you did not make the attempts, immediately change your password and enable 2FA.

Resetting your password

Click "Forgot password" on the login page. Enter your email address. You will receive a reset link valid for 1 hour. Choose a new, strong password. For security reasons, all active sessions are terminated when a password is reset.