Password and Security
Keep your account secure with strong passwords and security practices.
Password Requirements
Minimum Length: 8 characters
Must Include:
At least one uppercase letter
At least one lowercase letter
At least one number
At least one special character (!@#$%^&*)
Changing Your Password
Go to Settings → Account → Security
Click Change Password
Enter current password
Enter new password
Confirm new password
Click Update Password
Forgot Password?
Go to login page
Click Forgot Password
Enter your email
Check email for reset link
Click link (valid for 1 hour)
Create new password
Two-Factor Authentication (2FA)
What is 2FA?
Extra security requiring:
Your password (something you know)
Your phone (something you have)
Enabling 2FA
Go to Settings → Security
Click Enable Two-Factor Authentication
Scan QR code with authenticator app:
Google Authenticator
Authy
1Password
Enter 6-digit code
Save backup codes
Backup Codes
What: 10 single-use codes
When: Use if you lose your phone
Storage: Save in password manager or print
Disabling 2FA
Go to Settings → Security
Click Disable 2FA
Enter password
Enter current 2FA code
Confirm disable
Security Best Practices
Strong Passwords
Use Password Manager: 1Password, LastPass, Bitwarden
Unique per Site: Don't reuse passwords
Length Over Complexity: Longer is better than complex
Phishing Protection
Watch for fake emails:
Real Preppable emails: From @preppable.com only
Suspicious links: Hover before clicking
Urgent requests: We never ask for password via email
Public Wi-Fi
Avoid: Don't log in on public Wi-Fi
Use VPN: If you must use public Wi-Fi
Device Security
Lock Screen: Use PIN/biometric
Keep Updated: Install OS updates
Antivirus: Use on Windows/Android
Account Access Log
View Login History
Go to Settings → Security → Access Log
See recent logins:
Date and time
IP address
Device type
Location (city, country)
Suspicious Activity?
If you see unfamiliar logins:
Change Password Immediately
Enable 2FA
Review Team Members: Remove any ex-employees
Contact Support: Report the incident
Session Management
Active Sessions
See all logged-in devices:
Web browser sessions
Mobile app (future)
API tokens (future)
Sign Out Everywhere
Go to Settings → Security
Click Sign Out All Devices
You'll need to sign in again
Use when:
Lost or stolen device
Suspicious activity
Left logged in on public computer
Data Encryption
In Transit: SSL/TLS encryption
At Rest: AES-256 encryption
Passwords: bcrypt hashing (irreversible)
