- IP Whitelisting
- Extra Client Functionalities
- Login Attempts
- Two-factor Authentication
- Password Resets
- Secure Link Sharing
- File Upload Types
- General Security Settings
Security menu access
- Admins and staff: Log in, go to
Settings, and select Security under theBranding and Customisationsection.

- Clients: Access security options through My Account > Security.

Restrict access by IP (IP whitelisting)
You can control which IP addresses can access your organization’s admin area and the client area to restrict access to trusted sources. Upmind supports static IPs, staff-specific whitelists, and CIDR ranges.Avoid dynamic IPs to prevent accidental lockouts.
IP whitelisting from admin
To add an IP whitelist entry from admin, enter the IP address (required) and a Description (optional).
IP whitelisting for staff
For staff, IPs can be set on a per-user basis in the staff control panel or per API token. This overrides global settings.- As an admin, you can add a staff user under Settings > Staff Users.

- Click Create user.

- Secure with whitelist IPs.

Security. For more information, follow this guide.
How to find out my IP address
Visit https://ip.me.uk to check your current IP.Extra client functionalities
You can enable or disable the secure vault for notes and secrets at the client, lead, and contract product levels. Both staff and clients can access the vault, with all actions logged for security.
How to manage login attempts
The section Passwords & Login allows you to configure login security and attempts.| Field Name | Description |
|---|---|
| Allow client login by any email address | If enabled, clients can login using any email address in their account settings. |
| Allow client login by any active service identifier | If enabled, clients can login using any active service identifier, such as a domain name. |
| Max failed attempts | Control the number of failed login attempts before lockout. |
| Max failed 2FA attempts | Set maximum failed attempts for passwords and 2FA. |
| Lockout minutes | Define lockout duration in minutes. |
How to reset a password as staff/admin
If you want to change your password:- Go to My Account > Security.
- Enter your current and new password (minimum 8 characters, at least one letter and one number).
- Save changes.

- On the login page, click Forgot your password?
- Enter your email/username and request a reset link.
- Follow the email instructions to set a new password.


Secure link sharing
You can manage shared resource links. Set default expiration (in days) for shared links to protect sensitive resources.
How to manage upload file types
This relates to support tickets and allowed file types for attachments. Although all attachments are virus-scanned and flagged if issues arise, it’s best to restrict attachment types to those you expect to receive.- Go to Settings > File Uploads.
- Select which file types are permitted for uploads in the client area (enable Denied Download by Scan Status by ticking the boxes).
- All uploads are virus scanned, and suspicious files are flagged.

General security settings
You can control various access restrictions:- Limit viewing of client profiles and resources to users with a valid support PIN or linked tickets (non-admins only).
- Set the duration (in hours) for which access is granted after PIN entry or ticket assignment.


