DivePilot protects your account with hashed passwords, short-lived access tokens and permissions. There is no two-factor sign-in, so each person's own password is what keeps their account safe. This article sums up what you can put in a security or compliance questionnaire.
What the Privacy Policy lists
The Privacy Policy on the DivePilot website names these measures:
- Encryption for all data travelling between your browser and DivePilot.
- Passwords stored only in hashed form, never readable.
- Short-lived access tokens and refresh tokens that are replaced on every use.
- Access inside the app controlled by each person's permissions, see Permissions explained.
- Regular security reviews.
It also says that data is stored on servers in the European Union, that card numbers never reach DivePilot, that the app uses no advertising or tracking cookies and loads no third-party analytics, and that significant changes to the policy are announced by email. More in Your data, privacy and contracts.
Sign-in and sessions
- A password needs at least 8 characters, with a capital letter, a lower-case letter, a number and a special character.
- Sign-in allows about ten attempts a minute per internet connection. Accounts are never locked after failed attempts.
- A session lasts until 30 days after you last used DivePilot. Each person can be signed in on one device at a time: signing in elsewhere ends the earlier session within 15 minutes. See I keep getting signed out.
- A password reset link works for ten minutes, even though the reset email says one hour.
- A changed permission, or a deleted user, takes effect within 15 minutes.
- Sign-up, online booking, self-registration, waiver signing and dive log forms carry an automatic abuse check that runs in the browser and sets no cookies.
What does not exist
- No two-factor sign-in. Once your dive center's business email is confirmed, the password alone signs a person in, with no code from an app, a text message or an email.
- No single sign-on with Google, Microsoft or another provider.
- No sign-in history in the app and no alert about a new sign-in. Users only shows the date each person last signed in, in the Activity column (Last login on smaller screens). That date also moves when a session renews itself in the background.
So the rules on your side matter:
- Give every person their own login and never share one. Shared logins also sign each other out.
- Use a strong password that is not used anywhere else.
- On a shared computer, press Sign out before you walk away.
- When someone leaves, delete their user straight away, see Manage your team's accounts.
If you think someone else got in
- Reset the password with Forgot password? on the sign-in page. A reset ends the account's session on every device within 15 minutes. Changing the password under Edit profile does not.
- Check the permissions of the accounts involved on Users.
- Write to support@divepilot.app straight away. The Terms of Service ask you to report a suspected compromise immediately. See Contact support and check the system status.
Did this not answer your question? Contact support