User sessions persist even after 24 hours of inactivity, despite the policy stating 12 hours. This poses a potential security risk. Code review needed to ensure session expiration is properly implemented server-side.