Protection model
Security safeguards
This overview explains the protections customers can expect and the steps users should take to protect their accounts and records.
| Area | Standard | Operational meaning |
|---|---|---|
| 01 | Authentication and account access | Users must authenticate through approved account controls. Credentials are personal, and suspicious access may be blocked or require recovery. |
| 02 | Session management | Workspace and Admin sessions are separated and controlled. Confirmed Sign Out should revoke the active session and permit an immediate clean login. |
| 03 | Campaign ownership | Campaign controls help prevent conflicting active work and support safe pause, resume, stop, and recovery actions. |
| 04 | Secure communications | The service is intended to use encrypted network connections. Users should access only the official UONE domain and avoid untrusted links. |
| 05 | Access restriction | Administrative and standard user access are separated so each person sees only the controls appropriate to their role. |
| 06 | Audit and monitoring | Important access and account activity is recorded to support review, investigation, and responsible service operation. |
| 07 | Data handling | Uploaded records and downloaded results should be limited to authorised use, protected from public exposure, and retained only as long as required. |
| 08 | Incident response | Suspected compromise, incorrect access, or unexpected behaviour should be reported promptly so protective action can be taken. |
Personal information safeguards
Protection of personal information
Personal information is protected through layered technical and organisational safeguards appropriate to the nature of the information and the service risk.
Protected handling
Personal information is intended to be protected while transmitted and while retained by the service. Sensitive information should not be exposed through ordinary support channels or unnecessary downloads.
Controlled visibility
Access to sensitive information is restricted according to authorised responsibilities. Information may be masked by default, and sensitive access may be attributable through activity records.
Least privilege
Access governance
Access should be limited to the permissions required for each role, reviewed when responsibilities change, and removed promptly when no longer justified.
Role-based access
Standard and administrative responsibilities are separated so that users receive only the access needed for approved work.
Review and accountability
Administrative and sensitive actions should be attributable, access should be reviewed periodically, and suspected misuse should trigger investigation and corrective action.
User actions
What users should do
Protect access
Use a unique password, keep verification information private, sign out on shared devices, and report unexpected active-session messages.
Protect submitted-record information
Upload only authorised records, download results only when needed, restrict file access, and do not send sensitive records through ordinary support email.
Report a security concern
Contact support@uone.uk with the affected account or campaign reference and a description of the issue. Do not include passwords, verification codes, or unnecessary submitted-record data.
Security controls are reviewed and improved as the service, risks, and applicable obligations evolve. Material incidents are handled through documented detection, containment, assessment, communication, and recovery procedures.
Security information boundary
UONE describes security outcomes such as controlled access, protected sessions, activity records, data minimisation, and managed retention. It does not publish information that could weaken those controls, including credentials, internal service names, configuration values, security thresholds, or deployment details.
Continue exploring
Related public guidance
Continue to the privacy, trust, or account guidance relevant to your role.