Security & Privacy
Designed to minimise data exposure
OneAccess routes users to approved FUOYE services without collecting the passwords used by those services.
What OneAccess records
Where analytics are enabled, OneAccess records minimal operational telemetry such as page/service usage, device class and browser family. Raw IP addresses are not stored in analytics. Search terms are disabled from analytics logging by default.
What OneAccess does not collect
OneAccess does not collect or proxy passwords, Remita credentials, banking credentials or payment card details for the services it launches.
Administrative security
Administrative access uses role-based permissions, secure sessions, password authentication, administrator-enrolled registered-email MFA, rate limiting and tamper-evident audit records. Accounts that have completed MFA enrolment require the second factor on subsequent sign-ins. High-risk Tier-1 service URL changes require a separate administrator approval.
Reporting concerns
Use the University-Wide ICT Helpdesk to report suspected phishing, unauthorised portals, access problems or security concerns.