<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential Security on WebNotes</title><link>https://v2.webnotes.in/tags/credential-security/</link><description>Recent content in Credential Security on WebNotes</description><generator>Hugo</generator><language>en-IN</language><lastBuildDate>Sat, 20 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://v2.webnotes.in/tags/credential-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Zerodha client password and credential policy</title><link>https://v2.webnotes.in/zerodha-client-password-policy/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-client-password-policy/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha&amp;rsquo;s client password and credential policy&lt;/strong&gt; sets no password in the account-opening welcome email; the client creates the password at first login, and a mandatory second factor, the Kite App Code or an external time-based one-time password (TOTP), sits on top of it under the cyber-security framework SEBI mandated in its circular of 3 December 2018, enforced across brokers from 30 September 2022. The login is therefore two factors deep by design, and the account holder, not the broker, carries the loss from any credential misuse.&lt;/p&gt;</description></item></channel></rss>