Account and Website Security
Account credentials
Each person should use their own account, choose a unique password, and keep it private. Administrators should create named admin accounts instead of sharing one login.
Device safety
Users are responsible for securing devices, email accounts, browsers, and downloads used to access SperoMW. Sign out on shared devices and report suspected access promptly.
Protective controls
SperoMW uses password hashing, role-based access, protected project routes, CSRF controls, upload validation, server-side payment verification, audit logs, and HTTPS as part of its security approach.
Security monitoring
Access attempts and administrative changes may be logged. SperoMW may rate-limit, block, suspend, or investigate activity that threatens accounts, data, payment integrity, or service availability.
Incident response
If unauthorised access is suspected, SperoMW may reset credentials, revoke sessions or integrations, restrict downloads, preserve evidence, and contact affected users through the account email.
No absolute guarantee
No internet service can guarantee perfect security. Users should report concerns promptly and avoid sending passwords or payment credentials through project briefs or contact forms.
