Complete guide to operator account security settings on the C-Band Mailbox platform, including two-factor authentication, role-based access control, audit logs, data security obligations, and security incident reporting.
Security Settings
Protecting your operator account and renter data is a critical responsibility. The C-Band Mailbox platform provides comprehensive security features to safeguard your operation against unauthorized access, data breaches, and security incidents. This guide covers all security configuration options available in your operator dashboard, data security obligations under the Operator Terms & Conditions, and procedures for handling security incidents.
Two-Factor Authentication (2FA)
Two-factor authentication adds a critical layer of security to your account by requiring a second form of verification beyond your password:
Enabling 2FA
- Navigate to Security Settings in your operator dashboard
- Click "Enable Two-Factor Authentication"
- Choose your preferred 2FA method: authenticator app (recommended) or SMS
- Follow the setup instructions to link your authenticator app or phone number
- Enter the verification code to confirm the setup
- Save your backup codes in a secure location (these are used if you lose access to your 2FA device)
2FA Requirements
- Admin Roles: Two-factor authentication is required for all accounts with admin-level access. Admin accounts cannot disable 2FA once enabled.
- Staff Roles: 2FA is strongly recommended for staff accounts and may be required by your organization's security policy.
- All Accounts: We strongly recommend enabling 2FA on every operator account regardless of role.
API Key Management
If your operation uses API integrations with the C-Band platform:
- API keys are generated and managed through the Security Settings section
- Use unique API keys for each integration or application
- Rotate API keys periodically (recommended: every 90 days)
- Revoke unused or compromised API keys immediately
- Never share API keys in email, chat, or any unencrypted channel
Team Member Permissions - Role-Based Access Control
Control what each team member can access and do on the platform:
Admin Role
- Full access to all platform features and settings
- Can manage team members (add, remove, change roles)
- Access to billing, financial reports, and payout information
- Can modify operator profile, security settings, and notification preferences
- Can view and manage all renter accounts
Manager Role
- Access to mail management, customer profiles, and action request processing
- Can view financial summaries but not modify billing settings
- Can manage staff-level team members
- Access to compliance monitoring and document review
Staff Role
- Access to mail processing, scanning, and action request completion
- Can view renter profiles and communication history
- No access to billing, financial data, or settings
- Cannot manage other team members or modify account settings
Audit Logs
The platform maintains comprehensive audit logs that record every action performed on the platform:
- What Is Logged: Every login, logout, mail processing action, scan upload, action request update, billing event, profile change, and settings modification
- Information Recorded: Timestamp, user ID (which team member performed the action), action type, affected record (renter, mail item, invoice), and IP address
- Retention: Audit logs are retained for the duration required by your compliance obligations (minimum three years per Operator Terms & Conditions Section 8)
- Access: Audit logs are viewable by admin-level accounts through the Security Settings section
- Export: Audit logs can be exported as CSV for compliance reviews and external audits
Session Management
- Automatic Timeout: Platform sessions automatically expire after a period of inactivity (configurable, default: 30 minutes). You must re-authenticate to continue.
- Concurrent Session Limits: The platform limits the number of simultaneous active sessions per account to prevent credential sharing
- Active Sessions View: View all active sessions for your account and force-logout any session from an unrecognized device or location
Data Security Obligations
Per the Operator Terms & Conditions Section 7.2, operators must meet the following data security standards:
- TLS 1.2+ for Data in Transit: All data transmitted between your browser and the platform is encrypted using TLS 1.2 or higher. Ensure your browser and operating system are up to date to support these standards.
- AES-256 Encryption for Data at Rest: All renter data, documents, and scan images stored on the platform are encrypted using AES-256 encryption. This is handled by the platform automatically.
- Your Obligations: Secure your local environment - use strong Wi-Fi passwords, keep computers updated, run antivirus software, and follow the clean desk and screen locking policies covered in the Operator Training Program.
Password Policy
- Minimum Requirements: Passwords must be at least 12 characters and include a mix of uppercase letters, lowercase letters, numbers, and special characters
- Rotation Schedule: Change your password every 90 days (the platform will prompt you)
- Unique Passwords: Do not reuse passwords from other accounts or platforms
- Password Manager: Use a reputable password manager to generate and store strong, unique passwords
IP Restrictions (Optional)
For additional security, you can restrict platform access to specific IP addresses:
- Only allow connections from your business's IP address or VPN
- Block access from all other IP addresses
- Useful for preventing access from unauthorized locations
- Note: IP restrictions may prevent you from accessing the platform when traveling - configure exceptions as needed
Security Incident Reporting
If you suspect or discover a security incident (unauthorized access, data breach, compromised credentials, suspicious activity):
- Contain: Change passwords immediately, revoke compromised API keys, and force-logout all sessions
- Document: Record what happened, when it was discovered, what data may have been affected, and any actions taken
- Report: Notify C-Band Mailbox support immediately through the support ticket system
- Notify: Depending on the scope of the incident and applicable privacy laws (PIPEDA in Canada, state breach notification laws in the US), you may be required to notify affected renters and regulatory authorities
Annual Security Review Checklist
- Review and update all passwords
- Verify 2FA is enabled on all admin accounts
- Audit team member access and remove inactive accounts
- Review audit logs for any suspicious activity
- Rotate API keys
- Verify your browser and operating system are current
- Test your backup codes for 2FA
- Review physical security measures (locks, cameras, access logs)
For more security best practices, visit our Security Page. For staff training on data security, see Operator Training Program.
For additional support, visit our Help Center or submit a support ticket.