Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Registration & Authentication Security

For a complete description of the platform's security measures, see the Security page.

Authentication Factors

Up to four authentication factors are available (potentially more when using OpenID), depending on the user's registration server, but only one is mandatory. The other factors can be enabled as additional options.

Factor
RTS
Lite
CTS
ETS
SMS code to phone number Mandatory factor. Can be disabled by the administrator. Users can link their own phone number if the administrator allows it. In the internal environment (corporate network), the administrator can configure this step to be skipped in the administrator panel.
Email code / NTLM / OpenID Not available. Mandatory factor. Built-in brute force protection applies to Email code and NTLM. When using OpenID, any number of additional factors can be added — these are configured on the specific OpenID provider's side.
Personal password
(encryption key protection)
Optional factor. Set by the user in settings — more details.
PIN code Optional factor. Set by the user in settings. The administrator can make the PIN code mandatory for users through a role model rule.

Access and Device Restrictions by the Administrator

  • The administrator can prohibit connections from specific client platforms and limit the lifespan of user activations (sessions) — more details.
  • Access to
    CTS
    /
    eCTS
    can also be restricted by geographic boundaries by using connection filtering proxy in front of a corporate server — this becomes an additional security factor.
  • The role model supports "device corporate status": rules can be triggered based on the presence of a corporate certificate on the device — see role model rules.

Storage of Credentials and Keys on Client Devices

Credentials are stored in a protected area of the device's memory that cannot be accessed externally. Launching on rooted or jailbroken devices is blocked.


Platform How credentials are stored
iOS The keys are stored in the protected KeyChain area.
Android The keys are stored in the protected KeyStore area.
Aurora The keys are stored in a protected software vault.
Desktop Credentials are stored in system keychains (eXpress) or in their own encrypted storage (depends on the
ETS
application settings) — see desktop version credential storage for specific OSes.
Web Tokens stored in cookies are used.

Certification and Cryptography

  • Platform security is certified by FSTEC — more details.
  • Cryptographic strength has passed an independent audit.
  • Secure on-premise servers are available for enterprise customers (
    CTS
    /
    eCTS
    ), as well as server operation in isolated mode (
    ETS
    only).
  • Transport encryption uses TLS 1.3 and DTLS.
  • Enhanced qualified electronic signature (QES) and Russian GOST encryption are supported upon request.

Fraud and Phishing

Never share one-time SMS codes with anyone — without the code, it is impossible to log into an account using your phone number. Official eXpress SMS messages include a reminder not to share the code with third parties.

I received an SMS code for eXpress, and a stranger asked me to share it. What should I do?

If you receive one-time codes and then requests to share them, but you have not registered for eXpress yourself — someone may be trying to create or use a public account with your phone number. eXpress is a messenger, and if an attacker gains access to your account, they can send messages on your behalf. Never share SMS codes with anyone!

How do I restrict access to my account if I already shared the SMS code with attackers?

  • Download eXpress, log in with your phone number, and delete the account: Settings > Profile > three dots > (Actions with profile) > Delete profile, or contact eXpress support to do so. The account is deleted permanently.
  • If you do not want to delete the account — open Settings > Active sessions and terminate any sessions you do not recognize. Set a personal password for extra protection. Without the one-time SMS code and the personal password, an attacker will not be able to log in again.