Security
Schools trust us with their students' information. This is how we look after it, and how to tell us if you find a problem.
How the site is protected
- Encryption. Every connection uses HTTPS (with HSTS), and the website's connection to its database is encrypted. Names, email addresses, IP addresses, linked-account ids, support messages and invoice copies are encrypted with AES-256-GCM before they're stored; the keys are kept apart from the database and its backups.
- Signing in. Passwords are stored only as Argon2id hashes. Passkeys, and Google, Microsoft and school single sign-on, are supported. Site and school admins must use a passkey (two factors) for their admin powers. Repeated wrong attempts are slowed down and then blocked.
- Sessions. Session cookies are secure, HTTP-only and same-site, stored only as keyed hashes, and end after two hours idle unless you choose to stay signed in. You can sign out your other devices from your account page.
- The browser. A strict Content Security Policy lets pages run only the site's own code. Account pages can't be framed or cached. While you use a resource, your browser talks only to this site: fonts and outside data are fetched by our server.
- Least access. Teachers see only their own classes' students, and only for their classes' subjects. Every sign-in and account change is written to a security log.
- Keeping less. We collect only what the site needs, erase IP addresses after 30 days, and delete old activity and backups on a schedule (see the privacy notice).
- Payments. Cards are entered on Stripe's own page and never reach us.
Reporting a security problem
If you think you've found a weakness in the site, please tell us through the support page (choose "Security"), with enough detail for us to see it for ourselves. We'll reply within 5 working days, keep you told while we fix it, and thank you on this page if you'd like.
We won't take action against anyone who looks for problems in good faith and:
- uses only their own accounts (or test accounts) and never looks at, changes or keeps anyone else's information;
- doesn't slow the site down or disrupt anyone's use of it (no denial-of-service or automated scanning at volume);
- gives us a reasonable time to fix a problem before telling anyone else about it.
Students: if you find something, tell your teacher or tell us. You won't be in trouble for reporting it.
Our contact details for security reports are also at /.well-known/security.txt.
If something goes wrong
If personal information is ever accessed or lost without authority, we'll tell the schools and people affected, and the Office of the Privacy Commissioner where the Privacy Act requires it, as our school data agreement sets out.