Secure Password
Last updated 31 August 2026.
Your Kontala password protects everything in your books: your invoices and bills, your customer and supplier details, your bank transactions, your payroll, and your connection to HMRC. It is worth a minute of thought.
Why it matters
Accounts are rarely broken into by someone sitting there guessing. They are broken into with a password that leaked from somewhere else.
When any website is breached, the email addresses and passwords from it are collected and tried automatically against other services - and accounting software is well worth trying. Someone in your books can see your bank balances, your customers, and your staff's personal details, and can change figures you later file with HMRC.
So the single most useful thing you can do is make your Kontala password unique to Kontala. A clever password you also use for your email or an old shopping account is only as strong as the weakest site you gave it to.
What makes a password strong
Length beats complexity. A long password is far harder to break than a short, fiddly one. Aim for at least 12 characters, and more if you can.
Three or four unrelated words work well. Something like harbour-melon-cassette is quick to type, easy to remember, and hard to guess - as long as the words are genuinely unconnected to you and are not a phrase anyone would actually say.
Make it unique. Do not reuse a password from another site, and do not make a variation of one either. Kontala2026! next to Netflix2026! is not two passwords.
What to avoid
Anything someone could look up, guess, or find on your own website:
- Your pet's name, your children, your partner, or your own name
- Your business name, your trading name, or your domain
- Birthdays, anniversaries, postcodes, or phone numbers
- Keyboard runs such as qwerty123 or 111111
- A common word with predictable swaps, such as Pa55w0rd - the tools that crack passwords try those first
- Anything you have ever sent to someone in an email or a message
Use a password manager
A password manager is the practical way to have a different long password everywhere without remembering any of them. Your browser has one built in, and there are dedicated apps. You remember one strong master password, and it fills in the rest.
If you would rather not use one, write your password down and keep the paper somewhere physically safe. A password on paper at home is a much smaller risk than the same password on twenty websites.
What Kontala requires
Your password must be at least 8 characters. Treat that as the floor rather than the target: 8 characters is quick to break with modern hardware, so go longer.
There is no rule forcing you to change your password every few months, and you do not need to. Routine changes tend to produce weaker passwords, each a small edit of the last. A strong, unique password is better left alone until you have a reason to change it.
Change your password
Kontala changes passwords through the reset flow:
- Open the account menu, top right, and choose Change Password. Kontala signs you out and opens the reset page.
- Enter your Email address and choose Reset password.
- Open the email we send and follow the link to Choose a new password.
- Enter your new password and choose Save my new password.
Reset links work once and expire quickly, so use the most recent email. See My details and your password for the rest of your profile.
If you think your password has been exposed
Change it straight away using the steps above, and change it anywhere else you used the same one.
Then, if you are an owner or admin, open Users and check the list: remove anyone who should not be there, and deactivate accounts for people who have left. The audit trail shows what has been changed in your books and by whom.
If something looks wrong, email support@kontala.com. We will never ask you for your password, and you should never send it to us.
If someone sets a password for you
When an owner or admin adds you as a user, they set your first password and pass it to you directly. Change it once you are in, so that only you know it. See Add and manage users.
How Kontala protects your password
Kontala never stores your password itself, only a one-way hash of it, so it cannot be read back even by us. After 5 failed sign-in attempts in a row, the account is locked for 30 minutes, which makes guessing impractical.
If you would rather not manage a Kontala password at all, you can sign in with Google and let your Google account handle it.
More on this in How we keep your data secure.
I need help with...
View all categoriesArticles in this section