Protection across the workflow
Time-limited access
Access credentials expire after a limited period instead of remaining valid indefinitely.
Refresh rotation
Session renewal replaces refresh credentials so superseded values are not intended for continued use.
Session revocation
Password changes and administrator resets can revoke other signed-in sessions where the workflow indicates this action.
Identity re-checks
Sensitive profile changes may require the current password to confirm that the person making the request controls the account.
Actions customers should take
- Use a unique password and never send it to Sophia or support staff.
- Sign out when using a shared or borrowed device.
- Change the password immediately if the account may be compromised.
- Keep the operating system, browser and mobile application updated.
Visible signs and normal behaviour
- A user may occasionally need to sign in again after expiry or revocation.
- Changing a password may end sessions on other devices.
- Unexpected repeated login prompts should be reported after basic browser checks.
Controls reduce risk; they do not eliminate it.
No single control guarantees protection against every threat. Secure use also depends on accurate access decisions, protected devices, appropriate staff training and prompt reporting. We avoid claiming certifications that have not been independently verified.
