Trust and security

    Security at OneCredential

    OneCredential is designed to support identity, credential, and representative access governance in regulated healthcare environments.

    Security principles

    • Role-based access designed to limit information to authorised users and purposes.
    • Protected handling of identity and credential evidence.
    • Structured records of access decisions and relevant platform activity.
    • Separation from clinical, patient record, and internal hospital systems.
    • Ongoing monitoring and review of platform access and security events.

    Identity and access

    Access controls are designed around user roles and organisational responsibilities. Users are expected to protect their account credentials, use only authorised access, and promptly report suspected compromise or inappropriate activity.

    Data protection

    OneCredential applies technical and organisational measures intended to protect data during storage, processing, and transmission. The platform is designed to reduce unnecessary exposure of underlying evidence while still communicating the status information needed for authorised decisions.

    Security reporting

    If you believe you have identified a security issue involving OneCredential, please contact us with enough non-sensitive detail to help us investigate. Do not include passwords, private keys, credential documents, or other sensitive personal information in an initial report.