Security Criteria
Autosky features robust security features developed specifically to protect user access at the Client layer. The system adopts multiple layers of defense to mitigate risks related to compromised credentials, weak passwords, and accesses from suspicious origins.
With these implementations, the platform ensures a significant reduction in the risk of breaches, reinforcing the security of the environments without compromising operational fluidity, keeping authentications fast and straightforward for the end user.
Device Validation and Authentication
To ensure that access is being made from a trusted origin, the system requires the validation of the device used through a temporary code (Token).
Token Receipt: The validation code is automatically sent to the registered email. If the user cannot find it in their inbox, it is always recommended to check the spam folder.
Administrative Token: If there is a failure in email delivery or difficulty receiving it, an administrative token is available in the Client Settings tab. The administrator or authorized support partner can pass this code directly to the user.

Security Lockout: As a protection measure against intrusions, the system automatically inactivates the account after 15 invalid token entry attempts. If this occurs, the user will need to contact support to request reactivation.
Security Indicators on the Dashboard
Within the Client's user list, the AutoSky dashboard provides visual indicators that facilitate the security monitoring of each account.
Visual Indicators (Green): When a feature is enabled and fully functional, it is indicated in green. This includes alerts for MFA configured on the Client, MFA activated by the user, and Validated device.
Traceability: Through the dashboard, the administrator can accurately view which devices have already been validated by a specific user and what validation method was adopted for each of them.

Password and Rotation Policies
To prevent the use of vulnerable passwords, AutoSky enforces strict credential creation and maintenance policies. The system automatically rejects terms that are on compromised password lists and enforces strict formatting rules.
Complexity criteria: A valid password must contain at least 8 characters, mixing uppercase and lowercase letters, numbers, and symbols. It cannot contain parts of the user's name or email.
Force password change: The administrator can enable an option that forces the user to change their password on the next login. When this occurs, access to the environment is only granted after creating the new credential.
Expiration and rotation: Passwords have a default expiration period of 60 days. In addition, the system has a rotation policy that prevents the reuse of the last 5 passwords registered by the user.
Network Access Control (IP)
Autosky monitors connection origins. If a network address is listed on a blacklist (a list of IPs blocked due to security risks), the user's access will be automatically blocked. In these cases, it is recommended that the user attempt to log in from another trusted network or request an analysis and possible release from the administrator responsible for the environment.
Last updated
Was this helpful?
