Security
These terms describe how MobilityCloud is provided and how project, billing, participant, document and mobility evidence workflows are handled. MobilityCloud is powered by Xeotype.
1. Security commitment
MobilityCloud is designed to protect project data, participant records, uploaded evidence, billing information and account access through a practical security model suitable for a hosted project management platform.
2. Access control and administrator safeguards
- Users authenticate with individual accounts.
- Email verification may be required before normal platform use.
- Project access is invitation-based and scoped to specific projects.
- Roles can limit editing, viewing or module-specific access.
- Administrative panels are separated from user project modules.
- Impersonation and sensitive administrative actions should require a reason and audit logging.
3. Files, documents and evidence
Uploaded files are intended to be delivered through controlled application routes instead of public directory listing. Users should avoid uploading unnecessary sensitive data and should delete files that are no longer needed.
Project owners are responsible for reviewing permissions when inviting collaborators, facilitators, partner organisations or external contributors.
4. Operational controls
- HTTPS should be enforced for public access.
- Server firewall rules should restrict unnecessary inbound ports.
- Backups should be monitored, rotated and stored with appropriate access restrictions.
- Error logs and audit logs should be reviewed when incidents or unusual behaviour occur.
- Production configuration should avoid debug output and should protect secrets, database credentials and mail credentials.
5. User responsibilities
- Use strong, unique passwords and protect devices.
- Do not share accounts between people.
- Remove collaborators who no longer need access.
- Verify participant links before sending them publicly.
- Do not upload malware, unlawful files or unnecessary special-category data.
- Report suspicious activity immediately.
6. Security incidents and limitations
If MobilityCloud identifies a suspected security incident, it will investigate, contain the issue where practicable, preserve relevant logs, communicate with affected users where appropriate, and assess any legal notification obligations.
No online service can guarantee absolute security. Users should maintain their own copies of critical official files and should not rely on MobilityCloud as the sole archive for statutory or funder records.
7. Reporting vulnerabilities or suspected misuse
Please report suspected vulnerabilities, unauthorised access, exposed data, phishing, malware or account compromise to contact@mobilitycloud.eu. Include the affected URL, account email, project name where relevant, screenshots if safe, and steps to reproduce.
Do not access, modify, delete, download or disclose data that does not belong to you while investigating a potential vulnerability.
Company details
Legal review note
These documents are prepared as launch-ready platform policies. Because legal requirements can depend on the exact customer type, data flows, payment model, processors and jurisdictions involved, XEOTYPE SRL should periodically review them with qualified legal counsel.