All security controls
SECURITY CONTROL EXPLAINED

Protected sessions

Authenticated sessions are designed to avoid relying on one permanent browser credential. Short-lived access tokens support normal requests, while refresh-token rotation renews access and helps reduce the usefulness of older session material.

Protected sessions represented as a protected enterprise system
Protected sessions · Security by design
HOW THE CONTROL HELPS

Protection across the workflow

Time-limited access

Access credentials expire after a limited period instead of remaining valid indefinitely.

Refresh rotation

Session renewal replaces refresh credentials so superseded values are not intended for continued use.

Session revocation

Password changes and administrator resets can revoke other signed-in sessions where the workflow indicates this action.

Identity re-checks

Sensitive profile changes may require the current password to confirm that the person making the request controls the account.

YOUR ORGANISATION’S ROLE

Actions customers should take

  • Use a unique password and never send it to Sophia or support staff.
  • Sign out when using a shared or borrowed device.
  • Change the password immediately if the account may be compromised.
  • Keep the operating system, browser and mobile application updated.
WHAT USERS CAN EXPECT

Visible signs and normal behaviour

  • A user may occasionally need to sign in again after expiry or revocation.
  • Changing a password may end sessions on other devices.
  • Unexpected repeated login prompts should be reported after basic browser checks.
CLEAR SECURITY COMMUNICATION

Controls reduce risk; they do not eliminate it.

No single control guarantees protection against every threat. Secure use also depends on accurate access decisions, protected devices, appropriate staff training and prompt reporting. We avoid claiming certifications that have not been independently verified.