Account & Security
Sessions & account security
How Cernexa protects your password and signs you out after inactivity.
Cernexa applies sensible security defaults to accounts and sessions.
Password storage
Passwords are hashed with salted scrypt, a memory-hard key-derivation function. They are never stored in plaintext or in any reversible form, and Cernexa cannot recover or display your password — only reset it. Choose a strong, unique password (minimum 8 characters).
Inactivity timeout
For security, sessions end after 30 minutes of inactivity:
- The session is a sliding window — any activity rolls it forward, so you're never signed out mid-task.
- About a minute before timeout, a warning dialog appears with a countdown. Choose Stay signed in to continue, or Sign out now to leave immediately.
- If you do go idle, you're signed out and returned to the sign-in page with a "signed out due to inactivity" notice. This is enforced both in your browser and on the server, and it applies to the platform admin area too.
Staying secure
- Sign out on shared machines rather than relying on the timeout.
- Use a unique password and a password manager.
- Limit who holds owner/admin roles — those roles can manage sensitive configuration like integration keys. See Organization, members & roles.