Information security

Password Policy

v1.1
Updated Jul 2026 · Reviewed Jun 2026 · next review Jun 2027

Owner: Andrew James (CEO)

1. PURPOSE

This policy defines password requirements for all Halved Limited systems to protect against unauthorised access and meet Cyber Essentials requirements.

2. SCOPE

This policy applies to all passwords used to access:

Passwords that students and school staff set on the Halved platform itself are not covered by the scope above. They are governed separately by Section 9.

3. PASSWORD REQUIREMENTS

3.1 Minimum Password Standards

All passwords must meet the following minimum requirements:

3.2 Multi-Factor Authentication (MFA)

3.3 Password Management Requirement

All users must:

3.4 Admin Account Passwords

Administrative accounts require additional security:

Minimum length: 12 characters (must be different from standard account passwords)

MFA: Mandatory on all admin accounts

Uniqueness: Admin account passwords must be completely different from standard account passwords

4. PASSWORD CREATION GUIDANCE

4.1 Creating Strong Passwords

Good approaches:

Avoid:

4.2 Password Expiry

5. COMPROMISED PASSWORDS

If you suspect your password has been compromised:

6. NEW USER ONBOARDING

When a new team member joins:

7. COMPLIANCE

Failure to comply with this policy may result in:

8. TRAINING

All users receive password security training:

9. PLATFORM-USER PASSWORDS (HALVED PRODUCT)

Sections 1 to 8 of this policy concern Halved’s corporate systems, meaning the accounts staff use to run the company, such as Microsoft 365, Azure, GitHub and MongoDB Atlas. This section is separate. It governs passwords set by end users of the Halved platform, meaning students and school staff, through account setup, password reset and the in-app change-password form. The corporate requirements in Sections 1 to 8 do not apply to platform users, and the requirements in this section do not apply to corporate systems. Both scopes are stated explicitly so that the two are not read as one.

Where a school uses single sign-on with its own identity provider, Halved does not set or store a platform password for those users, and their passwords remain governed by the school’s own policy. The requirements below apply only where Halved sets the password.

9.1 Minimum Requirements

The following are enforced on the server, on every route that sets or changes a platform password. Any check performed in the browser exists only to give the user a helpful message and is not the control.

9.2 Cyber Essentials Alignment

Cyber Essentials requires, for accounts protected by a password alone, either a minimum length of 12 characters, or a minimum of 8 characters supported by a deny-list of common passwords. The student requirement meets the second route. The staff requirement meets the first route, with the deny-list added as a further layer. The higher bar for staff reflects their broader access to safeguarding data, to other users’ records and to administrative functions.

APPROVED BY:

Andrew James, CEO Halved Limited Date: 4th June 2026

Section 9 (Platform-user passwords) added and approved: 14th July 2026