Built for work worth protecting.
OneNod is designed around private projects, controlled review access, and a decision history people can understand.
Last updated: 31 August 2026Access controls
Projects begin private. Clients receive secure, project-specific links that workspace owners can revoke or replace.
Data protection
Production should enforce HTTPS, encrypt secrets and sensitive data, isolate customer records and use routinely updated infrastructure.
Authentication
Passwords should use strong salted hashes. Sessions should use secure HTTP-only cookies, suitable expiry and cross-site attack protection.
Files and uploads
Files should be validated, size-limited, malware-scanned and served through short-lived authorised URLs.
Audit trail
OneNod records uploads, comments, review access, change requests and approvals so owners know who did what and when.
Reporting a concern
Report potential security issues privately to [email protected] with enough detail to investigate.
Contact us at [email protected]. We’ll respond as soon as reasonably possible.