The technical detail your security team will ask for.
We're an Australian company building tools that handle sensitive workplace wellbeing data. Here's the technical posture, where we are on certifications, and how to report a vulnerability. For the customer-facing version see /trust or our Privacy Policy.
Last updated: 1 May 2026
Encryption + access
In transit
TLS 1.3 across every network hop. HSTS enabled. No HTTP fallback.
At rest
AES-256 at the storage layer. Free-text reflections (check-in notes, anonymous feedback) get an additional application-layer cipher.
Authentication
Email + password for admins (bcrypt-hashed). 4-digit PIN for packmates. Session tokens are scoped to a single workspace and can be revoked on demand.
Infrastructure access
Production access is limited to a small number of named people and is logged. There's no public admin surface.
Certifications + audits
We're early, and we'd rather be honest than impressive. We're not certified yet. Here's where we actually are, and this page moves as we do.
- Planned
SOC 2
Not certified yet. SOC 2 is on our roadmap. We'll update this page when an audit is genuinely underway, with no dates we can't stand behind.
- In place
Australian Privacy Principles
We're an Australian company and our customer data is hosted in Australia. See /privacy for our full posture. A Data Processing Agreement is available on request, email support@theschoolofplay.co.
- In place
Subprocessor list
Listed on our Privacy page: Vercel, Replit, Firebase, Stripe, Resend, PostHog, Sentry, and OpenAI. We notify customers before adding a new one.
Reporting a vulnerability
Found something that looks wrong? Tell us privately and we'll fix it fast. We don't prosecute good-faith research.
support@theschoolofplay.co
We acknowledge within 24 hours. Triage within 72.
- 1.Email us with steps to reproduce, the affected URL, and any proof-of-concept payload. Encrypt with our PGP key on request.
- 2.Don't access, modify, or exfiltrate other customers' data, even briefly. Use a test workspace.
- 3.Hold off public disclosure until we've shipped the fix (we'll keep you in the loop). 90-day default.
We don't run a paid bug bounty yet, but we credit researchers (with permission) on this page once a finding is resolved.
Operational practice
Backups
Daily encrypted snapshots, encrypted at rest. Restores are tested. Customer-initiated restore available on request.
Logging
Access is limited and logged. Admin actions are recorded to an audit trail (retained 12 months, 36 months on Enterprise).
Incident response
We monitor for issues and keep a public status page at /status. If an incident materially affects customer data, we notify affected admins and write it up.
Secret management
Production secrets in Vercel + Replit env vars (encrypted at rest, scoped to deploy). No secrets in git. Pre-commit secret scanner.
Procurement, audit, security questionnaire?
We answer every security questionnaire ourselves, usually within 48 hours. CAIQ + SIG Lite responses available on request.