Keeping your account secure
How Dudley protects your data, how organization MFA works, and everyday practices that keep accounts safe.
Your business data is sensitive, and protecting it is a shared responsibility. Dudley provides strong security by default; here’s how MFA and everyday habits make your account safer.
How Dudley protects your data
- Encryption in transit and at rest.
- Strict tenant isolation — your data is never mixed with another business’s.
- Audit logging of important account activity.
- Hardened cloud infrastructure with regular security updates.
Multi-factor authentication (MFA)
MFA adds a second step at login so a password alone isn’t enough. Dudley uses an authenticator app (TOTP) — for example Google Authenticator, 1Password, or Authy — not SMS.
MFA is available on Pro, Enterprise, and during a free trial. It is not available on paid Basic. An owner or admin turns it on for the whole organization; individuals cannot enable MFA only for themselves.
Require MFA for your organization
- Go to Settings → Organization (owners and admins).
- Under Multi-factor authentication (MFA), turn on Require MFA for all users in this organization.
- Save.
After you turn it on, anyone who hasn’t set up MFA yet is prompted the next time they sign in. Until they finish setup, they can’t reach the rest of the app.
Set up MFA when prompted
- Sign in with your email and password as usual.
- On Set up two-factor authentication, scan the QR code with your authenticator app (or open Can’t scan? and enter the key manually).
- Enter the 6-digit code from the app and choose Confirm and finish setup.
- Save your backup codes somewhere safe — Dudley shows them once at the end of setup. Each code works only once if you lose access to your authenticator.
Signing in after setup
After password entry you’ll be asked for a fresh 6-digit code from your authenticator app. If you can’t use the app, choose Use a backup code instead and enter one unused backup code.
Backup codes later
While signed in, you can check how many unused backup codes you have left and regenerate a new set (which invalidates the old ones) at /mfa/backup-codes/. Store any new codes securely.
If you lose both your authenticator and your backup codes, contact support so access can be restored safely.
Everyday best practices
- Use a unique, strong password.
- Only invite team members who need access, and use the right role.
- Remove or deactivate users promptly when they leave.
- Keep backup codes offline or in a password manager — not in an unlocked note on your phone.
Your data is yours, and it’s never sold.