Skip to content

Security

Security at 1410SMS

Schools hand us student records, staff data and fee collection. This is the short version of how that is protected. The Trust Centre carries the detail behind each point.

  • Encrypted in transit

    Portals, the mobile app and custom domains are all served over HTTPS. Unencrypted requests are refused rather than redirected.

  • Passwords never stored in plain text

    Passwords are stored as one-way cryptographic hashes. Nobody can read one back out of the database, and that includes us.

  • Strict tenant isolation

    Every query touching school data is filtered by the school identifier on the authenticated session, never one supplied by the client.

  • Audit-logged actions

    Administrative changes, subscription overrides and support impersonation are recorded with the acting user, timestamp and IP address.

  • Monitored continuously

    Database connectivity, background queues and error rates are monitored, with automated alerts on unhandled errors.

  • Honest about the roadmap

    Two-factor authentication and a public status page are planned, not shipped. We list them as roadmap rather than advertising them.

Reporting a vulnerability

If you believe you've found a security vulnerability in 1410SMS, please tell us directly rather than disclosing it publicly. We don't run a formal bug bounty programme yet, but we investigate every report we receive and will acknowledge it. Please give us a reasonable opportunity to investigate and address an issue before sharing details with anyone else.

Ready to get started?

Free for schools up to 40 students. No credit card required.