Security and Data
How children's and families' information is kept safe, and the independent checks the service is working towards. The privacy notice explains what is collected and why.
Where the Information Is Kept
- The database runs in London (UK), with Supabase. The web pages are delivered by Cloudflare. Neither provider uses the information for anything else.
- The school decides what is collected and who can see it. The service provider processes it only on the school's instructions.
- Records are kept as part of the school's safeguarding record, in line with the school's records retention policy.
Who Can Get In
- Every member of staff has their own login. Logins are created and switched off only by the school's administrators.
- Passwords are stored only in scrambled form (bcrypt) and cannot be read by anyone, including the school and the provider.
- The database itself checks every request, so a teacher's login cannot see office or admin information, and a parent can only ever see their own family.
- The office handover app can be used on one device at a time, and can be locked to a single registered device. Staff screens can be limited to the school's own network.
- Staff are signed out automatically at the end of each school day. Signing out, or an administrator switching a login off, ends access straight away.
- A second sign-in step, a code sent by email, can be switched on for staff and parents. An authenticator app option is planned.
- Repeated wrong passwords are blocked, and the office is told.
Checks at Collection
- A child is only handed over after two separate checks: the prep room checks the child out, and the office confirms who is collecting.
- The must-not-collect list is checked every time a child is sent for. A match stops the request and alerts the office and the safeguarding lead.
- Where a photo is held, staff compare the person at the desk with it. Photos are only compared by eye: there is no face recognition.
- If a child leaves a room and has not reached the office within a few minutes, or has not been collected when prep ends, the office and the safeguarding lead are alerted.
- Printable paper backups (registers, collection logs and contact sheets) let the school carry on if the internet or a device fails.
Independent Checks and Certifications
These are the checks schools and their IT advisers usually ask a supplier for. Their status is shown honestly and will be updated as each one is completed.
| Registration with the Information Commissioner's Office | Data protection registration for the service provider. | In progress |
|---|---|---|
| Data processing agreement | A written agreement between the school and the provider, listing the hosting providers used. | In progress |
| Data protection impact assessment | A pre-filled assessment for the school's data protection lead to review. | In progress |
| Cyber Essentials | The UK government-backed scheme for basic cyber security. | Planned |
| Cyber Essentials Plus | The same scheme, with hands-on testing by an independent assessor. | Planned |
| Independent penetration test | A specialist firm tries to break in and reports what it finds. Repeated every year and after major changes. | Planned |
| Hosting providers | Supabase and Cloudflare hold their own independent security certifications (for example SOC 2). [Provider to confirm the current certificates.] | Provider held |
The service is designed to help schools meet the Department for Education's cyber security standard for schools, for example by supporting a second sign-in step for staff.
If Something Goes Wrong
If personal data is lost, seen by the wrong person or changed without permission, the provider will tell the school straight away, so the school can report it to the Information Commissioner's Office within 72 hours where required.
Report a Security Concern
If you think you have found a weakness, or something doesn't look right, please tell the school office, or email [security contact email]. Please don't test the service without permission.