1. Security controls
VerificaOra uses access controls, password hashing, protected sessions, CSRF protection, 2FA, encrypted technical credentials, logging, usage limits and role segregation. Controls evolve according to risk and technical sustainability.
2. User responsibilities
Use unique passwords, protect devices and 2FA codes, sign out from shared sessions and never share credentials. Report suspicious access to info@uese.it.
3. Sensitive uploads
Remove unnecessary data, redact excessive information and confirm a lawful basis before upload. Avoid secrets, identifiable health data and third-party documents unless necessary.
4. Responsible disclosure
Report vulnerabilities to info@uese.it with a description, impact, reproduction steps and minimal evidence. Do not include personal data or unlawfully obtained content.
5. Prohibited testing
Destructive tests, access to others’ data, social engineering, denial of service, persistence, exfiltration, alteration, deletion or premature disclosure are prohibited. No reward programme exists unless agreed in writing.
6. Incidents and continuity
For a suspected incident, change passwords, check 2FA, preserve evidence and contact info@uese.it. UESE ITALIA S.p.A. applies assessment, containment, recovery and notification procedures where required.
