Security Best Practices in Sonas
Sonas holds your customer details, contracts and payment information, so we build security into the platform by default. This article explains the protections that are always on, the settings you can adjust, and the habits that keep your venue and your couples safe.
How Sonas protects your account
Device verification (two-factor authentication)
Whenever you sign in from a new or unrecognised device, Sonas sends a verification link to your email address. Until you click it, the login does not go through. This means that even if someone guesses your password, they cannot get in without also having access to your email.
You can review the devices linked to your account at any time under Profile → Known devices, and your login history appears in your account activity. If you see a device or login you don't recognise, remove the device and change your password.
How long a device stays verified
You sign in with your password as normal each time; device verification is separate and controls whether Sonas trusts the device you are signing in from. A verified device stays trusted for as long as you keep using it, with each sign-in extending the trust period. If a device goes unused for two weeks (the default), it is removed from your trusted devices and your next sign-in from it will ask you to verify by email again.
You can shorten this window in your Company settings if you prefer devices to need re-verification more often, for example if staff work from shared or personal devices. The minimum is one hour.
Automatic logout
Users are automatically logged out after 20 minutes of inactivity. This reduces the risk of someone using an unattended screen. This setting cannot be changed.
Session length
By default, a verified login lasts two weeks before you need to sign in again. You can shorten this in your Company settings if you prefer a tighter window, for example if staff often work from shared or personal devices. The minimum is one hour.
Best practices for you and your team
- Give each person their own login. Never share accounts or passwords. Individual logins mean the activity log always shows who did what, and you can remove one person's access without disrupting anyone else.
- Assign roles based on what each person needs. Not everyone needs admin access. Giving staff only the permissions their job requires limits the impact if any one account is compromised.
- Use strong, unique passwords. Aim for more than 12 characters and avoid names, dates or anything guessable. A password manager makes this easy by generating and storing strong passwords for you.
- Protect the email account behind Sonas. Device verification relies on your email, so your inbox is the key to your Sonas account. Make sure your email provider's own two-factor authentication is switched on.
- Be cautious with verification emails. Sonas sends a verification link when a new device signs in. If you receive one you didn't trigger, don't click it, and change your password. Sonas and your colleagues will never ask you for your password.
- Log out on shared devices. On reception iPads or other shared screens, log out when you finish rather than relying on the automatic timeout.
- Remove access promptly when someone leaves. Revoke a staff member's access as part of your leaver process. The same applies to couples: if an event is cancelled, remove their portal access too.
- Review your System Logs. Your System Logs record important changes across your account, including any change to your bank details, with who made the change and when. A quick periodic review helps you spot anything unexpected.
Payments: share bank details through Sonas, not email
We recommend keeping bank details out of email altogether. There are two practical reasons:
- Emails containing account numbers are often flagged as suspicious by mail providers, so your genuine email may land in spam or never arrive at all.
- It sets a clear, simple rule for your couples: payment details live in one trusted place. A well-known scam involves emailing couples "updated" bank details around the time a payment is due (see payment diversion fraud on Action Fraud). When your couples know you only ever share payment details through their portal, an unexpected email like that stands out straight away.
To set this up, add your bank details once under Venue Integrations → Bank Transfers. Couples will see them in their planning portal when making a payment, and on invoices and statements generated by Sonas. As an added benefit, any change to your bank details is recorded in your System Logs, including who changed them and when.
It also helps to set expectations early. A short line in your welcome email does the job:
"A quick note on payments: we only share bank and payment details through your planning portal, never by email. If anything about a payment ever seems unusual, just give us a call first."
If a couple asks about payment by email, point them to their portal rather than replying with account numbers.
Questions?
If you spot anything unusual on your account or want a hand reviewing your settings, get in touch with us through support and we'll help you check things over.
Updated on: 22/07/2026
Thank you!