image
  • Overview
  • Assurance Areas
  • Continuity Plans
  • Deployment Models
  • Evidence Room
  • Security
  • Support
  • Contact
Client Login Request Demo

Acceptable Use Policy

Effective Date: 01 July 2026

1. Purpose of This Acceptable Use Policy

TrustOps Portal is a secure assurance, continuity and compliance platform that helps organizations access approved records relating to backup assurance, recovery evidence, data hosting statements, audit documents, service continuity, tenant assurance and approved requests.

This Acceptable Use Policy explains how users may and may not use TrustOps Portal, the public website, the Evidence Room, Request Center and related services.

TrustOps Portal is designed to provide clear, controlled and approved assurance evidence. It is not designed to expose raw backups, cloud credentials, production databases or other clients' data. The TrustOps website copy already states that TrustOps is not a raw database access portal and does not expose passwords, cloud consoles, production credentials or uncontrolled backup files.

2. Who Must Follow This Policy

This policy applies to all users, including:

  • client executives
  • ICT directors and IT users
  • finance users
  • internal auditors
  • external auditors
  • authorized client approvers
  • ABNO/Lolla staff
  • CloudOps and technical teams
  • Customer Success teams
  • Legal and Compliance teams
  • Finance and commercial teams
  • consultants, advisers or third parties granted access
  • any visitor using TrustOps Portal website forms.

By using TrustOps Portal or submitting information through the website, you agree to use the platform responsibly, lawfully and only for authorized purposes.

3. Acceptable Use

You may use TrustOps Portal to:

  • view approved assurance records for your organization
  • access approved audit evidence
  • request backup assurance documentation
  • request recovery evidence or recovery test information
  • request data hosting or residency statements
  • request service coverage confirmation
  • submit approved continuity-related requests
  • track approved request status
  • download documents you are authorized to access
  • support audit, ICT, finance, compliance and governance processes
  • communicate with ABNO/Lolla through approved channels
  • manage assigned approvals where your role permits.

TrustOps Portal is intended to give users clear access to the right evidence based on their role, organization, product and deployment model. The UX instructions define the TrustOps design principle as "One portal. Role-based workspaces. Clear evidence. No technical confusion."

4. Authorized Access Only

You may access TrustOps Portal only if you have been authorized by your organization, ABNO/Lolla or the relevant service provider.

You must not:

  • access the Portal using another person's account
  • share your login details
  • allow another person to use your account
  • access records belonging to another organization
  • attempt to bypass permissions
  • attempt to access pages, files or records not assigned to your role
  • impersonate another user, auditor, client officer or ABNO/Lolla staff member.

Your access may be limited by:

  • organization
  • product
  • user role
  • evidence type
  • document status
  • approval status
  • request type
  • access duration
  • security classification.

5. Account Security Responsibilities

You are responsible for keeping your TrustOps account secure.

You must:

  • use your own login details
  • keep passwords confidential
  • protect MFA codes where enabled
  • use official work email where possible
  • log out after use on shared devices
  • notify ABNO/Lolla immediately if you suspect unauthorized access
  • notify your organization or ABNO/Lolla if your role changes
  • avoid using compromised, shared or public devices for sensitive access.

ABNO/Lolla may suspend access where misuse, compromise, suspicious activity or policy breach is suspected.

6. Prohibited Use

You must not use TrustOps Portal or the website to:

  • access unauthorized records
  • view another client's data
  • bypass access controls
  • attempt to access raw database backups
  • attempt to access cloud consoles
  • attempt to access production database credentials
  • upload malware, scripts or harmful files
  • interfere with Portal performance or availability
  • scan, attack, test or probe the Portal without written authorization
  • scrape, copy or mass-download records without approval
  • alter, falsify or misuse evidence documents
  • submit false requests
  • misrepresent your authority
  • harass, threaten, defame or abuse any person
  • use the Portal for unlawful, fraudulent or harmful purposes
  • share evidence with unauthorized persons
  • use personal email or personal storage for official evidence handling
  • attempt to reverse engineer, copy or resell the Portal.

7. Information You Must Not Submit Through Public Forms

Do not submit the following through public website forms, demo forms or ordinary contact channels:

  • passwords
  • database credentials
  • cloud credentials
  • production access keys
  • raw database backups
  • raw database files
  • highly sensitive system exports
  • confidential third-party data
  • payment card details
  • unnecessary national ID/passport documents
  • information belonging to another organization without authority.

The TrustOps website form guidance already requires users not to submit passwords, credentials, raw backup files or highly sensitive data through public forms.

Where sensitive information is required, ABNO/Lolla will provide approved secure instructions.

8. Evidence Room Acceptable Use

The Evidence Room is a controlled, read-only area for approved assurance and audit documents.

You may use the Evidence Room to:

  • view approved documents
  • download documents where permitted
  • support audit review
  • verify evidence validity
  • share evidence internally only with authorized persons
  • provide documents to authorized auditors where permitted.

You must not:

  • alter evidence documents
  • remove disclaimers or validity dates
  • present expired evidence as current
  • forward evidence to unauthorized persons
  • upload evidence to public or personal drives
  • use evidence for unrelated purposes
  • claim the evidence covers products, dates or services not stated in the document.

The TrustOps UX instructions require the Evidence Room to provide approved assurance documents only and not expose cloud consoles, credentials, production databases or raw backup files.

9. Request Center Acceptable Use

The Request Center may be used to submit approved requests such as:

  • Backup Assurance Report
  • Recovery Test
  • Data Hosting Statement
  • Audit Evidence Pack
  • Secure Data Copy
  • Tenant Data Export
  • Tenant-Level Recovery
  • Extended Backup Retention
  • Kenya-Resident Backup Copy
  • Dedicated DR Assessment
  • Auditor Support Session

Continuity Question.

You must ensure that every request is:

  • truthful
  • authorized
  • necessary
  • specific
  • submitted for a legitimate organizational purpose
  • supported by proper approval where required
  • limited to data or evidence your organization is entitled to request.

Submitting a request does not mean it is automatically approved, included, free, technically feasible or legally permissible.

10. Secure Data Copy and Backup Export Rules

Backup export, secure data copy and tenant data export are sensitive processes.

You must not request or expect:

  • informal backup sharing
  • backup delivery by ordinary email
  • backup delivery through WhatsApp
  • backup upload to personal drives
  • unencrypted backup transfer
  • release of shared SaaS platform database backups
  • release of another client's data
  • release without authorization and custody acceptance.

Approved data copy requests may require:

  • formal authorization
  • clear purpose
  • approved recipient
  • defined data scope
  • legal or compliance review
  • finance review where billable
  • encryption
  • secure transfer
  • custody acceptance

TrustOps record.

The TrustOps model supports secure data copy requests and controlled data export, but these must follow approval, encryption, access logging and custody procedures.

11. Shared SaaS Tenant Use

Some TrustOps-supported products operate on shared SaaS platforms.

For shared SaaS products:

  • clients may receive tenant-level assurance
  • platform backups are centrally managed
  • tenant data exports may be provided where approved
  • tenant-level recovery may be provided where technically feasible
  • full raw platform database backups are not released to individual tenants.

You must not request, attempt to access or claim entitlement to a full shared SaaS platform database backup unless expressly authorized by law and approved through the correct legal and technical process.

TrustOps distinguishes dedicated database assurance from shared SaaS tenant assurance, including platform backup assurance, tenant isolation statements, tenant-specific export requests and controlled tenant-level recovery procedures.

12. Auditor Acceptable Use

Auditors may only access TrustOps Portal where authorized.

Auditor access may be:

  • read-only
  • time-bound
  • document-specific
  • limited to approved evidence
  • logged
  • subject to confidentiality obligations.

Auditors must not:

  • attempt to access production systems
  • request database credentials
  • request cloud console access
  • access another client's records
  • copy evidence outside the approved audit purpose
  • share evidence outside the authorized audit team
  • rely on expired or revoked evidence as current.

13. Client Responsibilities

Clients are responsible for:

  • approving authorized users
  • removing users who leave or change roles
  • protecting downloaded evidence
  • ensuring auditors use evidence properly
  • protecting any approved data copy received
  • ensuring internal access controls
  • ensuring onward sharing is lawful and authorized
  • reporting suspected misuse or unauthorized access
  • ensuring requests are submitted by authorized persons
  • understanding that TrustOps is an assurance portal, not a raw infrastructure access portal.

14. ABNO/Lolla Rights

ABNO/Lolla may:

  • approve, reject or pause requests
  • verify user identity or authority
  • limit user access
  • revoke user access
  • monitor activity for security and audit purposes
  • remove unauthorized content
  • suspend accounts for suspected misuse
  • refuse unsafe backup or data export requests
  • require additional approval for sensitive requests
  • apply service charges where applicable
  • update this policy from time to time.

15. Monitoring and Audit Logs

TrustOps Portal may log activity for security, audit, compliance and operational purposes.

Logged actions may include:

  • login activity
  • failed login attempts
  • role changes
  • document views
  • document downloads
  • request submissions
  • approvals
  • rejections
  • comments
  • evidence uploads
  • custody acceptance
  • access grants
  • access revocations.

These logs may be used to investigate misuse, prove evidence access, support audit, protect clients and enforce this policy.

16. Security Incident Reporting

You must promptly report:

  • suspected unauthorized access
  • wrong evidence visibility
  • account compromise
  • suspicious downloads
  • accidental sharing of evidence
  • phishing or impersonation attempts
  • data sent to the wrong recipient
  • lost device containing TrustOps evidence
  • any request to bypass TrustOps controls.

Reports should be sent through the official support or contact channel provided by ABNO/Lolla.

17. Breach of This Policy

Breach of this Acceptable Use Policy may result in:

  • warning
  • account restriction
  • account suspension
  • account termination
  • removal of Evidence Room access
  • rejection of requests
  • notification to the client organization
  • legal or compliance review
  • disciplinary action for internal users
  • contractual remedies where applicable
  • reporting to authorities where legally required.

ABNO/Lolla may take urgent action without prior notice where necessary to protect the Portal, client data, evidence records, infrastructure, users or legal interests.

18. Relationship With Other Documents

This Acceptable Use Policy should be read together with:

  • TrustOps Portal Terms of Use
  • Privacy Policy
  • Data Protection page
  • Cookie Policy
  • applicable client agreement
  • applicable SLA/AMC/subscription terms
  • applicable CICS or cloud continuity arrangement
  • applicable data processing agreement
  • approved TrustOps evidence or request terms.

Where a signed client agreement provides stricter obligations, the stricter requirement shall apply.

19. Updates to This Policy

ABNO/Lolla may update this Acceptable Use Policy from time to time.

Updates may reflect:

  • security improvements
  • new TrustOps features
  • new evidence types
  • changes in legal requirements
  • new product coverage
  • operational lessons
  • client feedback
  • audit findings
  • risk controls.

The updated version will be posted on the website or Portal with a revised effective date.

20. Contact Us

For questions about acceptable use, access concerns, security issues or suspected misuse, contact:

TrustOps Portal Team

Email: info@abnosoftwares.com

Phone: +254 (0)705 597336

Website: trustopsportal.com

For product-specific support, clients should use their official support channel.

Login / Portal Acknowledgement Text

Use this on login, onboarding or first-time user access:

By accessing TrustOps Portal, I confirm that I am an authorized user. I agree to use the Portal only for legitimate organizational, audit, ICT, finance, compliance or governance purposes. I will not share my login credentials, access unauthorized records, request raw backups outside approved procedures or disclose evidence to unauthorized persons.

Button text:

I Agree and Continue

Short Footer Version

Use this as a short footer or legal-page summary:

TrustOps Portal may only be used by authorized users for approved assurance, continuity, audit, compliance and service-related purposes. Users must not attempt to access unauthorized records, raw backups, cloud credentials, production databases or other clients' data. Sensitive requests such as secure data copy, tenant export and recovery support require approval, secure handling and custody controls.

TrustOps Portal

Your assurance, continuity and compliance center.

  • Overview
  • Assurance Areas
  • Continuity Plans
  • Deployment Models
  • Evidence Room
  • Security
  • Support
  • Privacy Policy
  • Data Protection
  • Terms of Use
  • Acceptable Use Policy
  • Cookie Policy
+254 (0)705 597336
Phone
info@abnosoftwares.com
Email
© 2026 TrustOps Portal. All rights reserved.
Powered by ABNO and Lolla digital infrastructure.