Account Security
Last updated August 19, 2026
How we protect your account and credentials.
Passwords
- We never store your password in plain text — it is protected with strong one-way hashing (Argon2id), and we never log or email it.
- We favor length over complicated rules: long passphrases are stronger and easier to remember, so we don't force arbitrary composition rules or periodic resets.
- We require a minimum length and check new passwords against known breached-password lists (without ever sending your full password).
Signing in safely
- Password managers are encouraged, including copy-and-paste.
- We use temporary delays and additional verification after repeated failed attempts, rather than permanently locking you out.
- Sensitive actions (changing your email or phone, deleting your account, exporting data) require a recent password confirmation.
- After a password reset we sign you out everywhere and require a fresh sign-in.
What's next
We are moving toward passwordless sign-in options such as passkeys and WebAuthn.
Reporting a concern
If you suspect unauthorized access to your account, contact support@admito.ai. See also our Data Breach Notification policy.
