Security & acceptable use

Access is least-privilege

Each person sees only the modules an administrator has granted. Registrations stay locked until approved, and every role change is written to the audit trail.

Credential obligations

Do not share credentials or allow anyone else to use your account. Use the device and network controls your organisation requires, and lock unattended sessions.

Incident reporting

Report suspected compromise, data loss, misdirected information or unauthorised access to the organisation's security contact without delay.

Acceptable use

Use the hub lawfully, professionally and proportionately. Do not attempt to disrupt the service, bypass access controls, upload malicious content, or use it to harass or discriminate against any person.

Extraction and copying

Export the data you need through the built-in export features. Screen-scraping, bulk extraction, and copying the application's structure, workflows or calculation methods for use elsewhere are prohibited by the User Agreement.

Monitoring

Sign-in, access decisions, exports and governed configuration changes are logged proportionately for security and assurance purposes.

Decision-support only

Scores, rankings and predictive signals support professional judgement. They must never be the sole basis for a decision affecting a resident, an employee, a property or a disposal.