niCoSolutions
International policy baseline — product facts, legal requirements and planned capabilities are identified separately.

CONNECTED SERVICES

Connection Policy

This policy explains how a user starts an external account or email connection and how UniCo limits the resulting access.

Starting an authorization

Selecting Continue with Google, Continue with Microsoft, Connect Email, Allow email access, or confirming an external account expressly starts the corresponding authorization flow. By continuing, the user asks UniCo Solutions to process only the account information and permissions necessary for that connection and shown during the authorization process.

Information and permissions

The external service presents the permissions requested before access is granted. UniCo Solutions processes the account identifier, email address, connection status, granted permissions and limited operational metadata needed to provide and secure the requested connection. Mailbox content is processed only after the user separately allows mailbox access and only within the permissions granted.

Implemented

Proof of account control

A successful authorization through the official Google or Microsoft authorization service is treated as proof that the user controlled that external account during the authorization. UniCo does not require a separate email code on top of that completed authorization.

For private email, secure credential validation proves control of the submitted mailbox credentials and configured mail services; it is not represented as independent proof of legal ownership of an email address. The connection remains limited to the exact authorized Personal or Workspace context.

Implemented

Personal and Workspace boundaries

A Personal connection belongs only to its owner. A Workspace connection belongs only to that Workspace and requires active membership and the applicable permission. Confirming an external account never creates broader UniCo permissions, transfers a Personal connection into a Workspace, or permits access to another Workspace.

Implemented

Credentials, revocation and availability

Authorization credentials are handled through protected server processes and are not displayed in ordinary connection records or logs. A user can disconnect an available connection, after which local credential access is removed according to the connection design.

A visible connection option does not mean that an external service has been activated. If configuration is unavailable, UniCo reports that the connection is not available yet and does not weaken redirect, encryption or authorization checks.

Architecture foundation

Private and shared mailbox verification

Private mail systems do not provide one universal, compatibility-safe address-ownership check. A self-addressed challenge can fail for legitimate delegated or shared mailboxes that permit reading but not sending. UniCo therefore does not claim a stronger proof than credential control unless a reviewed verification method can preserve compatibility and exact Workspace authorization.