Skip to content
Security

The technical detail your security team will ask for.

We're an Australian company building tools that handle sensitive workplace wellbeing data. Here's the technical posture, where we are on certifications, and how to report a vulnerability. For the customer-facing version see /trust or our Privacy Policy.

Last updated: 1 May 2026

Encryption + access

In transit

TLS 1.3 across every network hop. HSTS enabled. No HTTP fallback.

At rest

AES-256 at the storage layer. Free-text reflections (check-in notes, anonymous feedback) get an additional application-layer cipher.

Authentication

Email + password for admins (bcrypt-hashed). 4-digit PIN for packmates. Session tokens are scoped to a single workspace and can be revoked on demand.

Infrastructure access

Production access is limited to a small number of named people and is logged. There's no public admin surface.

Certifications + audits

We're early, and we'd rather be honest than impressive. We're not certified yet. Here's where we actually are, and this page moves as we do.

  • Planned

    SOC 2

    Not certified yet. SOC 2 is on our roadmap. We'll update this page when an audit is genuinely underway, with no dates we can't stand behind.

  • In place

    Australian Privacy Principles

    We're an Australian company and our customer data is hosted in Australia. See /privacy for our full posture. A Data Processing Agreement is available on request, email support@theschoolofplay.co.

  • In place

    Subprocessor list

    Listed on our Privacy page: Vercel, Replit, Firebase, Stripe, Resend, PostHog, Sentry, and OpenAI. We notify customers before adding a new one.

Reporting a vulnerability

Found something that looks wrong? Tell us privately and we'll fix it fast. We don't prosecute good-faith research.

support@theschoolofplay.co

We acknowledge within 24 hours. Triage within 72.

  • 1.Email us with steps to reproduce, the affected URL, and any proof-of-concept payload. Encrypt with our PGP key on request.
  • 2.Don't access, modify, or exfiltrate other customers' data, even briefly. Use a test workspace.
  • 3.Hold off public disclosure until we've shipped the fix (we'll keep you in the loop). 90-day default.

We don't run a paid bug bounty yet, but we credit researchers (with permission) on this page once a finding is resolved.

Operational practice

Backups

Daily encrypted snapshots, encrypted at rest. Restores are tested. Customer-initiated restore available on request.

Logging

Access is limited and logged. Admin actions are recorded to an audit trail (retained 12 months, 36 months on Enterprise).

Incident response

We monitor for issues and keep a public status page at /status. If an incident materially affects customer data, we notify affected admins and write it up.

Secret management

Production secrets in Vercel + Replit env vars (encrypted at rest, scoped to deploy). No secrets in git. Pre-commit secret scanner.

Talk to us

Procurement, audit, security questionnaire?

We answer every security questionnaire ourselves, usually within 48 hours. CAIQ + SIG Lite responses available on request.