# How to set up security settings

Configure your account's security and privacy settings to protect sensitive data and ensure regulatory compliance.

May 21, 2026

## Manage login and password security

Setting strict login requirements helps prevent unauthorized access to your account and sensitive documents.

1. Go to **Settings** and select **Security**.

2. Toggle **Enable high password strength** to require users to create stronger, more secure passwords.

When this setting is enabled, passwords must:
   - Be at least **12 characters long**

3. Toggle Enable two-factor authentication (2FA) to require users to verify their identity using an authenticator app when signing in.

4. Click **Save** at the bottom of the page to apply your changes.

**Important:** Enabling this will force all users to change their passwords within seven days and every 90 days thereafter. This action cannot be undone once triggered.

**Learn more:** [How to enable two-factor authentication](https://help.getaccept.com/en/articles/5151177-how-to-enable-two-factor-authentication)

## Control data access and sharing

You can restrict what users see within the platform to maintain internal privacy and data hygiene.

- **Restrict access to other users' data:** When you enable this, users can only see their own data. Managers can still see data for their specific team members, while Admins retain full visibility across the entity.

- **Enable manual document link sharing:** If you want to ensure documents are only sent through official channels, you can disable this to prevent users from generating manual share links.

- **Restricted access to supplemental documents:** Turning this on prevents users from creating private documents in the attachment library, ensuring all shared content is visible to the organization.

## Configure data protection and consent

To comply with global privacy laws, you can manage how recipients interact with your documents and how their data is tracked.

1. Navigate to **Settings** > **Data protection & GDPR**.

2. Toggle **Document access consent** to require recipients to agree to your terms before they can view the document.

3. Enable **Collect consent before enable tracking** to give recipients the choice to opt out of analytics. If they opt out, they can still read the document, but you won't see their "page views" or "time spent" data.

**Note:** If a recipient refuses consent, they will be blocked from viewing the document entirely. Read more about GetAccept [privacy policy](/content/privacy-policy/index.html).

## Adjust certificate privacy settings

You can mask sensitive information on the final signature certificate to protect the privacy of your signers.

- **Email signed document:** This setting only applies to internal GetAccept users (the sender). When disabled, the sender will not receive the signed PDF via email.

- **Hide personal information:** This masks details like Social Security Numbers (SSN) used during eID signatures.

- **Mask IP or Email addresses:** You can choose to hide these specific identifiers from the audit log on the final PDF.

- **Remove audit log:** If necessary, you can remove the entire audit log from the certificate, though this is generally not recommended for legal traceability.

## Set up automatic document removal

Keep your account clean and comply with data retention policies by setting up automated deletion rules.

1. Locate the **Automatic document removal** section.

2. Set the timeframe (in months) for **Remove inactive documents** to delete drafts or Send-outs that have no recent activity.

3. Set the timeframe for **Remove signed documents** if your company policy requires deleting completed contracts after a certain period.

4. Enter a notification email address under **Notification before removal**.

**Important:** GetAccept will email this address before deletion occurs. Once documents are removed, they cannot be recovered.
