Legal and policy
Authorized Account Access Policy
How access to your systems is granted, controlled, and removed.
Scope
This policy covers every system Netex Security is given access to, including camera platforms, recorders, POS and inventory systems, and telecom carrier portals.
How access is granted
- Access begins with written authorisation from the client naming the systems and the scope of work.
- The client creates named user accounts. We do not use owner accounts, shared logins, or credentials belonging to an employee.
- Permissions follow the principle of least privilege: only what the agreed work requires.
- Where the platform supports it, multi-factor authentication is enabled.
How credentials are handled
- Credentials are stored in controlled systems, not in messages, spreadsheets, or shared documents.
- Credentials are never displayed publicly, never included in reports, and never discussed outside the authorised team.
- We will never ask a client to send a password over an unsecured channel.
How access is used
- Only for the activities the client has authorised in writing.
- Activity is attributable to a named user so the client can audit it.
- Any request that falls outside the agreed scope is referred back to the client rather than actioned.
Third-party platform terms
Carrier and platform agreements govern who may access those systems. It is the client's responsibility to confirm that third-party operational support is permitted under their agreements before access is granted. Netex Security will ask for that confirmation in writing.
Removal of access
- Access is removed when a person leaves the engagement, when scope changes, or when the engagement ends.
- The client should disable the accounts they issued as part of offboarding, and we will confirm when our use has ceased.
- Access reviews are carried out periodically for long-running engagements.
This policy was last reviewed in July 2026.
Questions about this policy? Contact us on +1 281 777 9249 or at info@netexsecurity.com.