Skip to main content
Protecting your workspace and your customers’ data is a shared responsibility. FusionDesk provides a layered set of security controls — from enforcing two-factor authentication across your team to restricting access by IP address — so you can match the security posture your organization requires. This guide walks through every configurable security setting in one place.

Two-Factor Authentication

Two-factor authentication (2FA) adds a second verification step at login, significantly reducing the risk of unauthorized access even if a team member’s password is compromised.

Enforcing 2FA for All Users

1

Open security settings

Navigate to SettingsSecurityAuthentication.
2

Enable workspace-wide 2FA enforcement

Toggle Require Two-Factor Authentication to On. A confirmation dialog will warn you that all users who haven’t set up 2FA will be prompted to do so on their next login.
3

Confirm the change

Click Confirm and Enable. From this point, any team member without 2FA configured is redirected to the 2FA setup flow the next time they log in and cannot access the workspace until setup is complete.
FusionDesk supports both authenticator app (TOTP, compatible with Google Authenticator and Authy) and SMS as 2FA methods. Authenticator apps are recommended as they do not depend on mobile network availability. Team members can manage their own 2FA device from ProfileSecurityTwo-Factor Authentication. Admins can revoke a specific user’s 2FA device (for example, if they lose their phone) from SettingsTeamMembers[Member]Revoke 2FA.

Session Timeout Policies

Session timeout settings control how long an authenticated session remains valid before the user must log in again. To configure session timeouts:
  1. Go to SettingsSecuritySessions.
  2. Set the Idle Timeout — the period of inactivity after which a session is automatically ended. The minimum is 15 minutes; the maximum is 7 days.
  3. Set the Absolute Timeout — the maximum total session duration regardless of activity. After this period, the user must re-authenticate even if they have been actively working. The minimum is 1 hour; the maximum is 30 days.
  4. Click Save Session Policy.
For teams handling sensitive customer data or operating in regulated industries, we recommend setting the idle timeout to 30 minutes and the absolute timeout to 8 hours to align with common compliance baselines.

IP Allowlisting

IP allowlisting restricts workspace access to connections originating from a list of approved IP addresses or CIDR ranges. This is particularly useful for organizations where agents only work from corporate offices or a fixed VPN. To configure IP allowlisting:
  1. Navigate to SettingsSecurityIP Allowlist.
  2. Toggle Enable IP Allowlist to On.
  3. Click + Add IP Address and enter either a single IPv4/IPv6 address or a CIDR range (for example, 203.0.113.0/24).
  4. Add a label for each entry to document what it represents (for example, “London Office” or “Corporate VPN”).
  5. Repeat for each address or range you want to allow.
  6. Click Save Allowlist.
Before enabling the IP allowlist, make sure your own current IP address is included in the list. If you save a restrictive allowlist that excludes your current connection, you will be locked out of your workspace. If this happens, contact FusionDesk support — the support team can unlock access for you.

Audit Logs

The audit log records every significant action taken in your workspace by any user, providing a tamper-resistant trail for compliance investigations and incident response.

What Gets Logged

Viewing and Exporting Audit Logs

  1. Go to SettingsSecurityAudit Logs.
  2. Use the Date Range, Actor (which user performed the action), and Event Type filters to narrow the log view.
  3. Click any log entry to expand it and see the full event payload, including before and after values for changed settings.
  4. To export, click Export LogsDownload CSV. The export includes all entries matching your current filter.
Audit log entries are retained for 12 months on Standard plans and 36 months on Enterprise plans.

Data Residency and Compliance

FusionDesk is architected to support organizations operating under data protection regulations, including GDPR.

GDPR-Ready Practices

FusionDesk supports data subject access requests (DSARs), the right to erasure, and data export for individual contacts directly from the customer record. Navigate to Customers[Customer]Privacy to initiate these actions.

Data Processing Agreement

A signed Data Processing Agreement (DPA) is available for all FusionDesk customers. Download it from SettingsAccountLegal Documents, or request a custom DPA via your account manager.
FusionDesk encrypts all data in transit using TLS 1.2+ and at rest using AES-256. Your data is hosted in ISO 27001-certified data centers, with automatic backups taken every six hours and retained for 30 days.
For advanced compliance requirements — including SOC 2 Type II reports, HIPAA Business Associate Agreements, custom data residency regions, or penetration test attestations — contact FusionDesk support at security@fusiondesk.in or reach out to your dedicated account manager. Enterprise customers receive a security review package including the latest audit reports and a completed security questionnaire template.