Skip to main content

🔐 Strong Password Security

How Spendesk keeps your account secure — and what you can do to help.

How Spendesk keeps your account secure — and what you can do to help.

For: All Spendesk users.

Password requirements

When creating or updating your Spendesk password, it must meet the following criteria:

  • At least 8 characters long

  • At least 1 uppercase letter

  • At least 1 lowercase letter

  • At least 1 number

💡 Tip: The longer and more unique your password, the stronger it is. Consider using a password manager (such as 1Password or Bitwarden) to generate and store strong, unique passwords for every service.

Compromised password detection

To help keep your account safe, Spendesk checks whether your password has appeared in a known data breach using Have I Been Pwned — a trusted public security database.

If your password has been previously compromised, you will be asked to choose a new one before continuing.

This check applies when:

  • Creating your Spendesk account

  • Changing or resetting your password (web only)

🔒 Privacy note: Your password is never shared or transmitted as part of this check. The verification is done securely and privately — only a partial hash of your password is compared against the database.

How Spendesk protects your password

Spendesk applies several layers of technical protection to keep your credentials safe:

Hashing and salting
Your password is never stored in plain text. It is converted into an irreversible fingerprint using the Bcrypt hashing algorithm, with a unique random value (salt) added. This means:

  • Even if our database were accessed, no one could recover your original password.

  • Two users with the same password will have completely different stored fingerprints.

Brute-force protection
After 5 consecutive failed login attempts, the system introduces an increasing delay between further attempts. All failed login attempts are logged with the email address, IP address, and browser information.

Password reset link expiry
If you request a password reset and do not use the link, it automatically expires 3 hours after being sent. This prevents old reset links from being exploited.

How to reset your password

If you have forgotten your password or need to set a new one:

  1. Go to the Spendesk login page.

  2. Click "Forgot your password?".

  3. Enter your email address and click Send.

  4. Check your inbox for the reset email and click the link inside.

  5. Enter and confirm your new password.

⚠️ Note: The reset link expires 3 hours after it is sent. If you did not receive an email, check your spam folder or request a new link.

Best practices to keep your account secure

  • Use a unique password for Spendesk — do not reuse passwords from other services.

  • Enable two-step authentication — a strong password alone is not enough. Set up an Authenticator app, the Spendesk mobile app, or SMS as a second factor.

  • Never share your password with anyone, including your Spendesk administrator or our support team.

  • Use a password manager to generate and securely store strong, unique passwords.

Frequently asked questions

Can Spendesk support see my password?
No. Passwords are stored as irreversible cryptographic fingerprints. No one at Spendesk — including the support team — can read your password.

What happens if I enter the wrong password multiple times?
After 5 failed login attempts, the system introduces an increasing wait time before you can try again. If you are locked out, use the "Forgot your password?" link to reset it.

Why am I being asked to change my password?
If Spendesk detects that your current password has appeared in a known data breach (via Have I Been Pwned), you will be prompted to set a new one before you can continue.

Does my password expire automatically?
No. Spendesk passwords do not expire on a set schedule. However, if your password is found in a breach database, you will be asked to update it.

Related articles

  • Set up two-step authentication (Authenticator app, SMS or Spendesk mobile app)

  • Legal framework: secure your access to Spendesk

  • Spendesk mobile app login

Did this answer your question?