Security information
Learn about what we do to keep your data safe and secure.
Phocas keeps your business data safe and secure, while also being easily accessible to the people who need it.
Watch this brief Phocas demo video and read the additional information below.
Security-related questions people often ask are:
Is my data safe?
How does Phocas encrypt passwords?
How is my data backed up?
Does Phocas actively monitor security risks?
Is Phocas SOC 2 and GDPR compliant?
Answers to these questions and more information can be found on the Security and Technology and Terms and Conditions pages on our website:

Platform
Security and Technology
Learn about our infrastructure (data security, encryption, and more), application, compliance, and operational practices

Terms and Conditions
General Data Protection Regulation (GDPR)
Learn about our GDPR compliance and what services we offer to help you meet your compliance obligations
Session timeout overview
When using Phocas, your session stays active for a while, so you don’t need to sign in repeatedly. However, to help protect your data and ensure system security, user sessions are designed to automatically expire (time out) after periods of inactivity or in specific situations. When this happens, you need to sign in again to continue working.
Your session will expire in the following situations:
When your administrator:
Forces you to sign out
Locks your user account
Changes your username or password
After a set time period:
Each session will automatically expire after 12 hours.
If you impersonate another user, the impersonation session will timeout after 1 hour.
Multi-factor authentication
Phocas doesn’t natively support multi-factor authentication (MFA), but if you’re looking for that level of security, you can set up single-sign on (SSO) for your Phocas site.
Last updated
Was this helpful?