UONE Trust & Support Centre ยท Trust

Security

The practical safeguards and shared responsibilities that support secure use of UONE.

Protection model

Security safeguards

This overview explains the protections customers can expect and the steps users should take to protect their accounts and records.

Authentication and account access

Users must authenticate through approved account controls. Credentials are personal, and suspicious access may be blocked or require recovery.

Session management

Workspace and Admin sessions are separated and controlled. Confirmed Sign Out should revoke the active session and permit an immediate clean login.

Campaign ownership

Campaign controls help prevent conflicting active work and support safe pause, resume, stop, and recovery actions.

Secure communications

The service is intended to use encrypted network connections. Users should access only the official UONE domain and avoid untrusted links.

Access restriction

Administrative and standard user access are separated so each person sees only the controls appropriate to their role.

Audit and monitoring

Important access and account activity is recorded to support review, investigation, and responsible service operation.

Data handling

Uploaded records and downloaded results should be limited to authorised use, protected from public exposure, and retained only as long as required.

Incident response

Suspected compromise, incorrect access, or unexpected behaviour should be reported promptly so protective action can be taken.

User actions

What users should do

Protect access

Use a unique password, keep verification information private, sign out on shared devices, and report unexpected active-session messages.

Protect submitted-record information

Upload only authorised records, download results only when needed, restrict file access, and do not send sensitive records through ordinary support email.

Report a security concern

Contact [email protected] with the affected account or campaign reference and a description of the issue. Do not include passwords, verification codes, or unnecessary submitted-record data.