Inoapps SecurePass

SecurePass is a secure service that allows employees to manage their Oracle Cloud password reset process even if they do not have a corporate email account – without having to contact your IT Helpdesk.


  • Automated self-service password reset
  • Robust, secure and tightly governed environment
  • No need for additional infrastructure
  • Administration console providing a full audit trail of all activity
  • Automated notification of exceptions and problems
  • Delivered as a Cloud solution - low TCO
  • Multi-country support
  • No additional installation
  • Simple, intuitive user interfaces


  • Self-service empowerment for your employees
  • Reduction in IT Support costs
  • Avoidance of delays in accessessing critical systems
  • Reduction in staff training effort


£2 to £20 per user per year

  • Free trial available

Service documents

G-Cloud 10



Becky Harris


Service scope

Service scope
Software add-on or extension Yes, but can also be used as a standalone service
What software services is the service an extension to Oracle Solutions
Cloud deployment model Public cloud
Service constraints No
System requirements
  • Oracle Cloud ERP
  • User having available mobile phone

User support

User support
Email or online ticketing support Email or online ticketing
Support response times 1 business day
User can manage status and priority of support tickets Yes
Online ticketing support accessibility WCAG 2.0 AA or EN 301 549
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support No
Support levels Inoapps support levels vary depending on the specification set out in relation to customer needs. We can offer a light touch solution to offer basic guidance through the process or a more hands on approach to API integrations. Inoapps provide a technical account manager for this work.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Inoapps provide user documentation but can also provide a more detailed training package if required.
Service documentation Yes
Documentation formats PDF
End-of-contract data extraction Inoapps do not hold data within the InoHub solution - it is a tool to convert and 'aim' data at the final location.
End-of-contract process At the end of the contract the access to use the tool ceases - there are no additional costs.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 10
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
  • Opera
Application to install No
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Application is fully mobile enabled with responsive theme so user experience is the same on both devices.
Accessibility standards WCAG 2.0 A
Accessibility testing We have tested this with multiple users and had no isses
What users can and can't do using the API We can import and export a wide variety of data through a series of API's.
API documentation No
API sandbox or test environment No
Customisation available Yes
Description of customisation Our service can be configured to meet customer requirements.


Independence of resources The Inohub product is hosted on an environment specific to that customer - high availability, low cost, no disruptions.


Service usage metrics Yes
Metrics types The Admin console provides a range of usage analytics
Reporting types Real-time dashboards


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Security Clearance (SC)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations European Economic Area (EEA)
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least every 6 months
Penetration testing approach ‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest Physical access control, complying with CSA CCM v3.0
Data sanitisation process No
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach Through API's
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
Data import formats
  • CSV
  • Other
Other data import formats
  • PFT
  • Excel

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks TLS (version 1.2 or above)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability In line with Oracle product SLA's
Approach to resilience
Outage reporting

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication Other
Other user authentication Specified as per customer requirements
Access restrictions in management interfaces and support channels Access is restricted by careful user profiling and monitoring for both management interfacing and support channels.
Access restriction testing frequency At least every 6 months
Management access authentication Public key authentication (including by TLS client certificate)

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information You control when users can access audit information
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification No
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications Yes
Any other security certifications The DBAAS service is covered by Oracle - see T&Cs

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach Inoapps utilise the Oracle DBaaS service for this product - the components are tracked in line with Oracle best practice and T&C. Any changes are assessed for potential security impact in line with both industry and Oracle best practice.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Please see Oracle product terms
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach Please see Oracle product terms
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Please see Oracle product terms

Secure development

Secure development
Approach to secure software development best practice Conforms to a recognised standard, but self-assessed

Public sector networks

Public sector networks
Connection to public sector networks No


Price £2 to £20 per user per year
Discount for educational organisations No
Free trial available Yes
Description of free trial First Month Free


Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑