Security approach
Security is considered across website hosting, restricted access, server side validation, enquiry processing and operational monitoring. TOMIO reviews safeguards as the service develops, but no website can promise absolute security.
Public enquiry protection
The Contact service uses validation and anti abuse controls intended to reduce automated misuse and protect legitimate enquiries. Successful enquiries receive a TOMIO reference for correspondence.
- Server side request validation
- A mathematical challenge and automated submission controls
- Restricted request rates and origin checks
- Protected confirmation and reference handling
Restricted administration
Administration functions require authorised staff authentication and are not public customer accounts. Access restrictions, staff sessions and related security controls protect those areas.
Information you should not send
The website does not process online orders or payment cards. Do not include passwords, payment card details, government identity records, health records or other unnecessary sensitive information in a general enquiry.
Secure connections
TOMIO expects the production website to be delivered through an encrypted HTTPS connection. A secure connection protects information in transit but does not remove every online risk.
Reporting a security concern
If you believe you have found a security concern, use the Contact page, select the most appropriate enquiry type and provide a clear, responsible description. Do not publicly disclose personal information, credentials or details that could increase harm.
Contact TOMIONo unsupported assurance
This page describes general website safeguards. It does not claim a security certification, guarantee uninterrupted service or disclose sensitive implementation details.
