- Audit logging
- Single sign-on (SSO)
- Multi-factor authentication
Audit logs capture authentication events, authorization and privilege changes, and user and administrator actions.
Logs are encrypted and held in immutable storage with MFA-restricted access, and can be exported on request.
Onebox supports single sign-on for end users, authenticating against the customer's identity provider via SAML 2.0.
Administrators authenticate through OAuth against Onebox's internal authentication service.
2FA is enforced across product and administrator access. TOTP authenticator apps are supported natively, and FIDO2 / WebAuthn is available where contractually required.
- Password security
- Session management
- Input validation
- Location data
- Mobile app distribution
For customers not using SSO, password complexity is configurable: minimum length, mixed case, digits and symbols.
Passwords are never stored in plaintext. Resets are issued as time-limited tokenised links, and privileged account resets require an approval workflow.
Sessions time out after a period of inactivity and require re-authentication. The timeout is configurable per tenant within defined security limits.
All API endpoints apply server-side input validation and sanitisation. Error messages shown to users are generic, while full detail is written to the audit log.
Onebox does not access or collect device location or GPS data. No current or planned features require this permission.
Onebox mobile apps are distributed only through the Apple App Store and Google Play Store, published under the Onebox Ibérica account.



