Protection across the workflow
HTTPS by default
Supported web traffic is served over HTTPS so credentials, records and session information are not sent as readable plain text.
Identity verification
TLS certificates allow compatible devices to verify that they are communicating with the intended L2S Proximity service.
Integrity in transit
Encrypted transport helps detect tampering while requests and responses travel across networks.
Secure integrations
Connected services should use authenticated HTTPS endpoints and protect their credentials throughout the integration lifecycle.
Actions customers should take
- Use a supported, up-to-date browser or the approved mobile application.
- Do not continue past browser certificate or security warnings.
- Avoid signing in through untrusted shared devices or networks.
- Keep integration credentials outside source code and rotate them when exposure is suspected.
Visible signs and normal behaviour
- The address bar should show https:// on L2S Proximity pages.
- Passwords and one-time codes should never be requested through ordinary support messages.
- Report certificate warnings, unexpected redirects or suspicious login pages immediately.
Controls reduce risk; they do not eliminate it.
No single control guarantees protection against every threat. Secure use also depends on accurate access decisions, protected devices, appropriate staff training and prompt reporting. We avoid claiming certifications that have not been independently verified.
