User Login Policy & Procedures

AP Safety Alert — Authentication Standards & Account Security Guidelines

Effective: June 2026 · Version 1.0

1. Purpose & Scope

This policy establishes the standards and procedures governing user authentication, account access, and credential management for the AP Safety Alert platform. It applies to all users — including administrators, staff, and end users — who access the system.

The goal is to ensure that only authorized individuals can access the platform, protecting sensitive detection data, personal safety information, and system configurations.

2. Account Creation & Access

Invitation-Only Registration

New accounts are created exclusively by platform administrators via an email invitation. Self-registration is not permitted. Users may not share, transfer, or reassign accounts.

User Roles

Each account is assigned one of the following roles at creation:

  • Admin — Full access to all settings, user management, detection data, and system configuration.
  • User — Standard access to monitoring, alerts, watch targets, and personal account settings.

Account Activation

Upon receiving an invitation email, users must click the secure activation link within 48 hours. Expired links require the administrator to re-send an invitation.

3. Authentication Requirements

Login Method

Authentication is handled exclusively through the Base44 platform's secure login system, which uses email-based verification. No passwords are stored by AP Safety Alert directly.

Session Management

Sessions are time-limited and expire after a period of inactivity. Users should log out of shared or public devices immediately after use.

Device Trust

Users are responsible for ensuring that devices used to access the platform are secured with a screen lock, up-to-date operating system, and reputable antivirus software.

  • Do not access the platform on public Wi-Fi without a VPN.
  • Do not save login credentials in shared browsers.
  • Do not allow others to use your authenticated session.

4. Credential Security Standards

Email Address

The registered email address serves as your unique identity on the platform. Keep it current and ensure your email account itself is secured with a strong password and two-factor authentication (2FA).

Protecting Your Access

Since login links are delivered via email, securing your email account is critical:

  • Enable 2FA on your email provider (Gmail, Outlook, etc.).
  • Use a unique, strong password for your email account (12+ characters, mixed types).
  • Never forward or share login links with anyone.
  • Report suspicious login emails to your administrator immediately.

5. Monitoring & Suspicious Activity

Access Logging

All login events and significant actions within the platform are logged. Administrators may review access logs for compliance and security auditing purposes.

Unauthorized Access

If you suspect your account has been accessed without your authorization:

  • Contact your administrator immediately to have your account suspended.
  • Change the password on your linked email account.
  • Review recent detection events and alert logs for any unauthorized changes.
  • Do not attempt to investigate system access on your own.

6. Account Recovery

Lost Access

If you lose access to your registered email address or cannot log in, contact your platform administrator. Administrators can re-send an invitation to an updated email address.

Recovery Process

Account recovery follows these steps:

  • User contacts administrator with identity verification (name, registered email).
  • Administrator verifies identity through a secondary out-of-band method.
  • Administrator deactivates the old account and sends a new invitation.
  • User activates the new account within 48 hours.

7. Account Suspension & Termination

Grounds for Suspension

Accounts may be suspended or terminated by an administrator for the following reasons:

  • Violation of the Acceptable Use Policy.
  • Suspected unauthorized access or credential compromise.
  • User no longer requires access (role change, departure from organization).
  • Failure to comply with this login policy.

Procedure

Terminated accounts lose all access immediately. Data associated with the account is retained per the platform's data retention policy. Users are notified of termination via the email on file unless the account is suspended for security reasons.

8. User Responsibilities

By using AP Safety Alert, each user agrees to:

  • Never share login links, sessions, or access credentials with any other person.
  • Log out from all sessions when using a shared or public device.
  • Immediately report any suspected security incident to an administrator.
  • Keep the email address associated with the account active and secure.
  • Use the platform only for its intended personal safety and security purposes.
  • Comply with all applicable laws regarding the use of surveillance and detection technology.