Skip to content

Password requirements and best practices

What the portal insists on, what actually makes a password strong, and how to change yours.

1 min readReviewed 17 September 2026

Changing your password

Settings → Security → Password. You are asked for your current password, then the new one twice. You stay signed in on the machine you change it from.

If you cannot remember the current one, sign out and use Forgot password instead — the reset link goes to your registered email address.

What makes a password strong

Length, not decoration. A long passphrase of ordinary words beats a short one with symbols substituted into it, and it is far easier to type on a phone. Four unrelated words is a better password than P@ssw0rd!2026.

Two rules matter more than any of the complexity advice:

  • Never reuse it. The realistic threat is not somebody guessing your password; it is somebody taking it from a website that lost its database and trying it here.
  • Use a password manager. Then the password is long, unique and unremembered, which is the point.

For the firm

The people worth being strict with are your own staff, because their accounts reach every client’s documents. In order of effect:

  1. Two-factor authentication on every CPA and admin account. This does more than any password rule.
  2. A password manager the firm actually pays for, so nobody is inventing passwords.
  3. Removing accounts promptly when somebody leaves, from Users.

If you think a password has been exposed

Change it, then turn on two-factor authentication if it is not already on. Check the document activity history for anything you do not recognise, and tell support. See Activity history.

This did not answer it?

Sign in and write to us from Help & Support inside the portal — a message from there arrives with your firm and your account already attached, so nobody has to ask you which is which.

Sign in to Pertavo