ISO Mate checks every new password against a large database of passwords exposed in known data breaches. If your chosen password appears in a breach, ISO Mate blocks it and asks you to pick a different one. The check is built to protect your privacy: your actual password never leaves the server.
When the check runs
The breach check runs any time a password is set or changed, including:
- Registration: when you create your account.
- Password reset: when you reset a forgotten password from the login page.
- Invited user setup: when an invited user sets their first password.
- Admin user creation: when an administrator creates a user with a password.
- Setting or changing your password: in Security Settings, from the profile menu.
How your privacy is protected
The check uses a technique called k-anonymity. ISO Mate hashes your password and sends only the first five characters of that hash to the breach lookup service, never the password and never the full hash. The service returns a batch of possible matches, and ISO Mate compares them locally to see whether your password is among them. Because only a short, non-identifying fragment ever leaves the server, the security benefit comes with no cost to the confidentiality of your credentials.
The breach lookup also fails safe. If the service is slow or unreachable, the check is skipped for that attempt rather than blocking you, so an outage never stops you from setting a password.
What happens if a password is rejected
If the password you chose has been found in a data breach, you see a clear message asking you to choose a different one. Pick a strong, unique password that you do not use anywhere else, and you can continue.
Password requirements
Alongside the breach check, every password must meet these rules:
- Length: at least 12 characters and at most 128.
- Character mix: at least one uppercase letter, one lowercase letter, one number, and one special character.
- Not compromised: not found in known data breaches.
- Not reused: not one of your last five passwords.
Changing your password signs you out everywhere else
When you change your password while signed in, ISO Mate signs you out of every other active session and device. The session you are working in stays signed in, so you keep your place, but every other browser or device has to sign in again with the new password.
If other sessions are signed out, you receive an in app notification letting you know. If you did not expect it, treat it as a possible sign that someone else had access, and review your account security. Resetting a forgotten password from the login page works the same way. If you sign in with Google and have never set a password, you are asked to re-authenticate with Google before you can set one for the first time.
What this does not change
- No forced rotation: you are not asked to change your password on a schedule.
- Existing passwords unaffected: the check applies only when a new password is chosen.
Tips for a strong password
- Use a long passphrase rather than a single word.
- Use a unique password for ISO Mate that you do not reuse on other sites.
- Consider a password manager to generate and store strong passwords.
- Enable two-factor authentication for an extra layer of protection.
Related articles
Care about security from day one? Start your free 14-day trial and see how ISO Mate protects your account.