Security
Security at 1410SMS
Schools hand us student records, staff data and fee collection. This is the short version of how that is protected. The Trust Centre carries the detail behind each point.
Encrypted in transit
Portals, the mobile app and custom domains are all served over HTTPS. Unencrypted requests are refused rather than redirected.
Passwords never stored in plain text
Passwords are stored as one-way cryptographic hashes. Nobody can read one back out of the database, and that includes us.
Strict tenant isolation
Every query touching school data is filtered by the school identifier on the authenticated session, never one supplied by the client.
Audit-logged actions
Administrative changes, subscription overrides and support impersonation are recorded with the acting user, timestamp and IP address.
Monitored continuously
Database connectivity, background queues and error rates are monitored, with automated alerts on unhandled errors.
Honest about the roadmap
Two-factor authentication and a public status page are planned, not shipped. We list them as roadmap rather than advertising them.
Reporting a vulnerability
If you believe you've found a security vulnerability in 1410SMS, please tell us directly rather than disclosing it publicly. We don't run a formal bug bounty programme yet, but we investigate every report we receive and will acknowledge it. Please give us a reasonable opportunity to investigate and address an issue before sharing details with anyone else.
Ready to get started?
Free for schools up to 40 students. No credit card required.