# Security (https://yapl.app/en/docs/user-guides/account/security)

# Account Security

Protect your YAPL account with strong passwords and secure authentication practices. This guide covers password management, account verification, and security best practices.

## Accessing Security Settings

1. Click **Settings** in the sidebar navigation
2. Select **Account** tab
3. Find security options

## Password Management

### Password Requirements

YAPL requires passwords to be:

| Requirement        | Details                     |
| ------------------ | --------------------------- |
| Minimum length     | 8 characters                |
| Uppercase          | At least 1 uppercase letter |
| Number             | At least 1 number           |
| Special characters | Recommended                 |

### Changing Your Password

Password changes are handled securely via email:

1. Go to **Settings > Account**
2. Find **Password** section
3. Click **Reset Password**
4. Check your email for a password reset link
5. Click the link in the email
6. Enter your new password
7. Confirm your new password
8. Your password is updated

<Callout type="warn">
  For security, password changes require email verification. You cannot change your password
  directly in the app without receiving a reset link.
</Callout>

### Password Tips

**Do:**

- Use at least 12 characters
- Mix uppercase and lowercase
- Include numbers and symbols
- Use unique passwords for YAPL
- Consider a password manager

**Don't:**

- Reuse passwords from other sites
- Use personal information (birthdays, names)
- Share your password
- Write passwords in plain text
- Use common patterns (123456, password)

## Email Verification

Email verification is handled automatically during account registration. When you sign up:

1. A verification email is sent to your registered address
2. Click the link in the email to verify
3. Your account is activated

<Callout type="info">
  If you didn't receive the verification email during registration, check your spam folder or contact support for assistance.
</Callout>

## Account Recovery

### Forgot Password

If you forget your password:

1. Go to the login page
2. Click **Forgot Password**
3. Enter your email address
4. Check your email for reset link
5. Click the link
6. Enter your new password
7. Log in with new password

### Recovery Email

Ensure your email is:

- Current and accessible
- Verified
- Checked regularly

### Recovery Issues

If you can't access your account:

1. Check spam folder for reset email
2. Verify you're using the correct email
3. Wait a few minutes for email delivery
4. Contact support if issues persist

## Session Management

### Active Sessions

Your account may have multiple active sessions across:

- Different browsers
- Multiple devices
- Various locations

### Session Security

Best practices:

- Log out from shared computers
- Review active sessions periodically
- Revoke suspicious sessions

### Logging Out

To log out:

1. Click your profile avatar
2. Select **Log Out**
3. Session ends immediately

To log out everywhere:

1. Go to **Settings > Account**
2. Find **Sessions** section (if available)
3. Click **Log Out All Sessions**

## Security Best Practices

### Account Protection

| Practice         | Description                    |
| ---------------- | ------------------------------ |
| Unique password  | Don't reuse from other sites   |
| Regular updates  | Change password periodically   |
| Secure email     | Protect your email account too |
| Device security  | Lock your devices              |
| Browser security | Use up-to-date browsers        |

### Recognizing Threats

**Phishing Emails:**

- Check sender address carefully
- Don't click suspicious links
- YAPL won't ask for password via email
- Report suspicious emails

**Social Engineering:**

- YAPL support won't ask for passwords
- Verify requests through official channels
- Be cautious of urgent demands

### What to Do If Compromised

If you suspect account compromise:

1. **Change password immediately**
2. **Log out all sessions**
3. **Check account activity**
4. **Review workspace access**
5. **Contact support** if needed

## Account Data

### Your Data

Your account stores:

- Personal information (profile)
- Authentication credentials (hashed)
- Preferences and settings
- Activity history

### Data Protection

YAPL protects your data with:

- Encrypted passwords (never stored in plain text)
- Secure connections (HTTPS)
- Access controls
- Regular security audits

## Account Deletion

### Considerations Before Deletion

Before requesting deletion, consider:

- All your data will be removed
- You'll lose access to all workspaces
- Action cannot be undone
- Transfer ownership if you're an owner

### Requesting Deletion

To delete your account:

1. Contact support
2. Verify your identity
3. Confirm deletion request
4. Account scheduled for removal

<Callout type="error">
  Account deletion is permanent and cannot be reversed. All your data, including activity history,
  will be permanently removed.
</Callout>

## Support Access

### When to Contact Support

Contact support for:

- Account lockout issues
- Email change requests
- Security concerns
- Suspicious activity reports
- Account recovery assistance

### Security Contact

For security-related issues:

- Use official support channels
- Include relevant details
- Don't share passwords in tickets
- Respond to verification requests

## Troubleshooting

### Cannot Change Password

- Verify current password is correct
- Check new password meets requirements
- Ensure passwords match
- Try refreshing the page

### Not Receiving Reset Email

- Check spam/junk folder
- Verify correct email address
- Wait a few minutes
- Request new reset link
- Contact support if persistent

### Account Locked

If your account is locked:

1. Wait for the lockout period (if applicable)
2. Use password reset
3. Contact support for immediate assistance

## Related Topics

- [Profile Settings](/docs/user-guides/account/profile-settings) - Personal information
- [Preferences](/docs/user-guides/account/preferences) - Display settings
- [Registration](/docs/getting-started/registration) - Account creation