Security best practices
Protecting financial data and user access is a top priority at DPO. Follow the best practices below to keep your account secure.
Protecting Your DPO Account
Use two-step verification to add an extra layer of security to your login.
Update passwords regularly and use strong credentials.
Enforce book-level security rules to strengthen access control across your organization.
Enable Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an additional layer of protection to your account. With MFA enabled, you must verify your identity using a second factor (such as a mobile authentication app) in addition to your password.
Why MFA is important:
- Protects against stolen or leaked passwords
- Prevents unauthorized account access
- Reduces risk of phishing attacks
To enable MFA:
- Go to Account Settings
- Navigate to MFA
- Activate Multi-Factor Authentication
- Follow the setup instructions
We strongly recommend enabling MFA for all users, especially administrators and approvers
Administrators can also enforce MFA at Book level under: Admin → Password Policy

Use Strong, Unique Passwords
Your password is your first line of defense.
We recommend creating passwords that:
- Contain at least 12 characters
- Include uppercase and lowercase letters
- Include numbers and special characters
- Are not reused across other services
- Do not contain personal information or company names
Avoid simple passwords such as:
- Simple passwords like
Password123 - Company name + year
- Reused passwords from other systems
Strong passwords significantly reduce the risk of unauthorized access.
Change Passwords Regularly
Regular password updates help reduce the risk of long-term exposure.
We recommend changing passwords:
- Periodically based on your company’s internal security policy
- Immediately if suspicious activity is detected
- After any known credential exposure
To change your password:
- Go to Account Settings
- Enter your Current and your new secure password
- Confirm your new password
- Click Save to apply the changes

Configure a Custom Password Policy
Administrators should configure a password policy to strengthen account security and protect financial data.
- Go to Admin → Password Policy.

- Enable Require MFA to enforce multi-factor authentication for your Book.
(Each user must activate MFA individually in their Profile.)

- Define password requirements for User and Administrator roles
- Set minimum length, complexity, and expiration period

- Use Advanced Settings to require special characters, uppercase/lowercase letters, or numbers.

- Add banned words to prevent weak or predictable passwords (e.g., company name or common terms).

Recommended policy guidelines:
- Minimum password length of at least 12 characters.
- Complexity requirements (letters, numbers, symbols).
- Mandatory MFA for sensitive roles.
These measures significantly reduce the risk of unauthorized access.
Monitor Account Activity
Encourage users to:
- Report unusual login attempts
- Review approvals and changes regularly
- Inform administrators if suspicious behavior is detected
Early detection helps prevent security incidents.
Summary of Recommendations
For maximum security when using DPO:
✔ Enable Multi-Factor Authentication
✔ Use strong, unique passwords
✔ Change passwords regularly
✔ Implement a password policy
✔ Assign permissions responsibly
✔ Monitor account activity
Any Questions?
Our support team is happy to help:
Email: support@digitalpurchaseorder.com
Phone: +1 888 376 7254
Or schedule a free demo – we look forward to hearing from you.
Updated on: 18/02/2026
Thank you!
