Skip to Content
AdministrationSecurityOverview

Security

Configure SSO, SCIM provisioning, and security settings for your organization.

SAML SSO requires Business plan. SCIM requires Enterprise plan.

Security Overview

Authentication Options

MethodPlan Required
Email/PasswordAll
Google OAuthAll
SAML SSOBusiness+

Provisioning Options

MethodPlan Required
Manual InviteAll
SCIM 2.0Enterprise

Security Settings

Access at OrganizationSecurity

Session Settings

  • Session timeout: Auto logout after inactivity
  • Concurrent sessions: Limit simultaneous logins
  • Remember device: Trust device duration

Password Policy

  • Minimum length: Require longer passwords
  • Complexity: Require special characters
  • Expiration: Force periodic changes
  • History: Prevent reuse

Two-Factor Authentication

  • Optional: Users can enable
  • Required: All users must enable
  • Admin required: Only admins must enable

HTTP Security Headers

Penvio includes security headers on all responses to protect against common web attacks:

HeaderValuePurpose
X-Content-Type-OptionsnosniffPrevents MIME type sniffing
X-Frame-OptionsDENYPrevents clickjacking
X-XSS-Protection1; mode=blockEnables XSS filtering
Referrer-Policystrict-origin-when-cross-originControls referrer information
Content-Security-PolicyConfigured for app domainsPrevents XSS and injection attacks
Strict-Transport-Securitymax-age=31536000; includeSubDomainsForces HTTPS connections
Permissions-PolicyRestrictedLimits browser feature access

These headers are automatically applied and require no configuration.

Best Practices

  1. Enable SSO when possible
  2. Require 2FA for admins
  3. Set reasonable session timeouts
  4. Review audit logs regularly
  5. Use SCIM for large organizations
Last updated on