Italia Quality applies technical and organisational controls proportionate to the service and treats security/data integrity as part of community trust.
1. Principles
Least privilege, access separation, authentication, secure session management, credential protection, backups, updates and logging are reference principles.
2. Credentials
Passwords are handled through application hashing and must not be shared. Users should use strong passwords and protect the email/device linked to the account.
3. Sessions
Sessions use technical cookies with security flags compatible with HTTPS. Users should log out from shared devices and report suspicious access.
4. Uploads
Uploaded files and images are subject to application controls compatible with the system. Malware, scripts, disguised files or content designed to exploit vulnerabilities must not be uploaded.
5. Logging
Security logs and metadata may be retained to prevent abuse, investigate anomalies and protect rights under the Privacy Policy and data minimisation.
6. Incidents
Following an incident UESE assesses containment, recovery, evidence and notification duties, including Articles 33 and 34 GDPR where applicable.
7. Providers
External providers are assessed by role, data, security and continuity. API keys should remain server-side except where architecture requires browser keys appropriately restricted by domain and privilege.
8. Responsible disclosure
Suspected vulnerabilities should be reported to info@uese.it without exploitation beyond what is strictly needed to demonstrate the issue, without accessing third-party data and without premature publication.
9. Limits
No control eliminates all risk. Security also depends on browsers, devices, providers and user behaviour.
10. Key legal references
- Regolamento (UE) 2016/679 – GDPR
- D.lgs. 196/2003 – Codice in materia di protezione dei dati personali