Security and evidence by design.
How Mandate One protects tenant boundaries, accounts and learning records.
Tenant isolation
Customer-owned users, learning records, audit events, notifications and configuration are tenant-scoped. Platform operations are separated from customer learning evidence.
Identity controls
Password policy, lockout, time-limited recovery tokens, forced password change, email-based two-step verification and security-stamp session revocation are supported.
Evidence integrity
Completion, certificate and governance records are immutable. Audit packs include manifests, hashes, activity history and administrative adjustments.
Operational controls
Security headers, request throttling, antiforgery protection, health checks, structured logging and customer-approved support windows form part of the application design.
Production deployment
Production hosting should use managed secrets, persistent Data Protection keys, encrypted backups, monitored mail delivery, a production database and documented recovery testing.