A strong password is your first line of defense. This guide covers password requirements, how to reset a forgotten password, and best practices for password security.
Password Requirements
Zenovay passwords must meet these criteria:
| Requirement | Minimum |
|---|---|
| Length | 8 characters |
| Uppercase letters | 1 |
| Lowercase letters | 1 |
| Numbers | 1 |
Strong Password Tips
For better security, consider:
- 12+ characters
- Mix of letters, numbers, symbols
- No dictionary words
- No personal information
- Unique to Zenovay (not reused)
Use a Password Manager
Password managers like 1Password, Bitwarden, or Dashlane generate and store strong, unique passwords for each site.
Resetting a Forgotten Password
If you can't remember your password:
Go to Login Page
Navigate to app.zenovay.com/login.
Click Forgot Password
Click the Forgot password? link below the login form.
Enter Your Email
Enter the email address associated with your Zenovay account.
Check Your Email
Look for an email from noreply@zenovay.com with the subject "Reset your password".
Click Reset Link
Click the Reset Password button in the email.
Create New Password
Enter your new password twice to confirm.
Log In
Use your new password to log in. MFA will be required if enabled.
Password reset links expire after 1 hour for security.
Changing Your Password
To change your password while logged in:
Go to Account Settings
Navigate to Settings → Account.
Find Password Section
Scroll to the Password section.
Click Change Password
Click the Change Password button.
Enter Passwords
- Current password: Your existing password
- New password: Your desired new password
- Confirm: Retype the new password
Save Changes
Click Update Password.
Password Security
What Makes a Weak Password
Avoid these common mistakes:
- Dictionary words: "password", "welcome"
- Personal info: birthdays, names, pet names
- Simple patterns: "123456", "qwerty", "abc123"
- Keyboard patterns: "asdfgh", "1qaz2wsx"
- Previously breached passwords
Checking Password Strength
Zenovay shows password strength as you type:
- Weak: Red indicator, minimal requirements only
- Medium: Yellow indicator, meets requirements
- Strong: Green indicator, exceeds requirements
Have I Been Pwned?
Check if your password has been exposed in data breaches:
- Visit haveibeenpwned.com/Passwords
- Enter your password (securely hashed, never stored)
- If found, change it immediately
Password with Social Login
If you signed up with Google or GitHub:
Setting a Password
You can add a password for email login:
- Go to Settings → Account
- Click Set Password
- Create a password meeting requirements
Why Add a Password?
- Backup login method if social provider is unavailable
- Required for some API operations
- Enables email/password login option
Troubleshooting
Reset Email Not Received
- Check spam/junk folder
- Verify you're using the correct email
- Add
noreply@zenovay.comto contacts - Wait a few minutes (can be delayed)
- Try requesting again after 5 minutes
Reset Link Not Working
- Links expire after 1 hour
- Each link can only be used once
- Request a new reset link
- Clear browser cache and try again
"Password Already Used"
We don't allow reusing recent passwords:
- Use a genuinely new password
- Don't cycle through old passwords
- Consider using a password manager
Password Not Accepted
If your new password is rejected:
- Ensure it meets all requirements
- Avoid common passwords
- Try a longer, more complex password
- Check for leading/trailing spaces
Account Locked
Too many failed login attempts will temporarily lock your account:
- Automatic unlock: After 15 minutes
- Manual unlock: Use password reset
- Contact support: For persistent issues
Password and MFA
Password changes don't affect MFA:
- Your authenticator app continues working
- Security keys remain valid
- Backup codes remain valid
If you suspect your account is compromised, change both your password and regenerate MFA backup codes.
Best Practices
Do
- Use a unique password for Zenovay
- Use a password manager
- Enable MFA for extra security
- Change password if you suspect compromise
- Log out from shared devices
Don't
- Reuse passwords across sites
- Share your password
- Write passwords in plain text
- Use obvious personal information
- Ignore breach notifications
Enterprise Password Policies
Enterprise PlanEnterprise accounts can enforce:
- Minimum password length
- Complexity requirements
- Password expiration
- Password history (prevent reuse)
- Account lockout policies
Password vs Passkeys
The industry is moving toward passkeys, which eliminate passwords entirely. Zenovay supports WebAuthn, which will enable passwordless login as the technology matures. See WebAuthn Setup.
Next Steps
- Set up MFA for additional security
- Review security best practices
- Account recovery options