Trust Center
Password Policy
Effective date: July 22, 2026
Strong credential practices are one of the most practical ways to reduce account compromise, business email compromise, and unauthorized access.
Purpose
This Password Policy provides guidance for protecting business accounts, systems, and data through stronger credential practices, multi-factor authentication, and responsible access management.
Password and Passphrase Guidance
Use unique passwords or passphrases for each business system and account.
Use longer passphrases where supported instead of short or easily guessed passwords.
Avoid passwords based on company names, user names, seasons, dates, addresses, common phrases, or reused personal passwords.
Use a reputable password manager where appropriate to reduce reuse and improve secure storage.
Multi-Factor Authentication
Clover Technologies strongly recommends multi-factor authentication for email, remote access, cloud applications, administrative portals, backup platforms, finance systems, and other sensitive business services.
Privileged Accounts
Administrative access should be limited to authorized users with a business need.
Privileged accounts should use MFA and should not be shared between users.
Administrative access should be reviewed when employees change roles, leave the organization, or no longer need elevated rights.
Service accounts should be documented and protected according to their level of access.
Credential Handling
Do not send passwords through email, chat, or tickets unless an approved secure method is used.
Do not share MFA prompts, authentication codes, recovery codes, or password reset links.
Report unexpected MFA prompts, suspicious login alerts, or password reset emails immediately.
Change credentials promptly when compromise is suspected.
Account Lifecycle
Organizations should promptly notify Clover Technologies when users are hired, terminated, transferred, or no longer require access so that account changes can be completed according to the service scope.
