Wherehouse

Password Policy

Last updated on: 15 September 2026

This policy applies to every Wherehouse user account.

Password length

Passwords must be at least 12 characters. The application rejects shorter passwords at registration and at every password reset.

Complexity

Every new password must include all of the following:

  • At least one upper-case letter
  • At least one lower-case letter
  • At least one number
  • At least one special character (any character that is not a letter or a number)

The password must not include any part of the user's name. We treat first name, last name, username, and the local part of the email address as name parts. Tokens of three or more characters from those fields are blocked.

Password age

  • Minimum age: 1 day. A password cannot be changed again until 24 hours after it was set. This stops cycling through history to reuse an old password.
  • Maximum age: 365 days. After 365 days the current password still proves identity, but login does not issue a new session token. The user must set a new password that meets this policy.

Password history

You cannot reuse any of your latest 10 passwords.

Contact

Questions about this policy: [email protected]. Security reports: [email protected].