Two-Factor Authentication
Two-factor authentication (2FA) adds a second verification step at login, significantly reducing the risk of unauthorized access even if a team member’s password is compromised.Enforcing 2FA for All Users
1
Open security settings
Navigate to Settings → Security → Authentication.
2
Enable workspace-wide 2FA enforcement
Toggle Require Two-Factor Authentication to On. A confirmation dialog will warn you that all users who haven’t set up 2FA will be prompted to do so on their next login.
3
Confirm the change
Click Confirm and Enable. From this point, any team member without 2FA configured is redirected to the 2FA setup flow the next time they log in and cannot access the workspace until setup is complete.
Session Timeout Policies
Session timeout settings control how long an authenticated session remains valid before the user must log in again. To configure session timeouts:- Go to Settings → Security → Sessions.
- Set the Idle Timeout — the period of inactivity after which a session is automatically ended. The minimum is 15 minutes; the maximum is 7 days.
- Set the Absolute Timeout — the maximum total session duration regardless of activity. After this period, the user must re-authenticate even if they have been actively working. The minimum is 1 hour; the maximum is 30 days.
- Click Save Session Policy.
For teams handling sensitive customer data or operating in regulated industries, we recommend setting the idle timeout to 30 minutes and the absolute timeout to 8 hours to align with common compliance baselines.
IP Allowlisting
IP allowlisting restricts workspace access to connections originating from a list of approved IP addresses or CIDR ranges. This is particularly useful for organizations where agents only work from corporate offices or a fixed VPN. To configure IP allowlisting:- Navigate to Settings → Security → IP Allowlist.
- Toggle Enable IP Allowlist to On.
- Click + Add IP Address and enter either a single IPv4/IPv6 address or a CIDR range (for example,
203.0.113.0/24). - Add a label for each entry to document what it represents (for example, “London Office” or “Corporate VPN”).
- Repeat for each address or range you want to allow.
- Click Save Allowlist.
Audit Logs
The audit log records every significant action taken in your workspace by any user, providing a tamper-resistant trail for compliance investigations and incident response.What Gets Logged
Viewing and Exporting Audit Logs
- Go to Settings → Security → Audit Logs.
- Use the Date Range, Actor (which user performed the action), and Event Type filters to narrow the log view.
- Click any log entry to expand it and see the full event payload, including before and after values for changed settings.
- To export, click Export Logs → Download CSV. The export includes all entries matching your current filter.
Data Residency and Compliance
FusionDesk is architected to support organizations operating under data protection regulations, including GDPR.GDPR-Ready Practices
FusionDesk supports data subject access requests (DSARs), the right to erasure, and data export for individual contacts directly from the customer record. Navigate to Customers → [Customer] → Privacy to initiate these actions.
Data Processing Agreement
A signed Data Processing Agreement (DPA) is available for all FusionDesk customers. Download it from Settings → Account → Legal Documents, or request a custom DPA via your account manager.
For advanced compliance requirements — including SOC 2 Type II reports, HIPAA Business Associate Agreements, custom data residency regions, or penetration test attestations — contact FusionDesk support at
security@fusiondesk.in or reach out to your dedicated account manager. Enterprise customers receive a security review package including the latest audit reports and a completed security questionnaire template.
