[{"data":1,"prerenderedAt":137},["ShallowReactive",2],{"trust-security":3},{"id":4,"title":5,"body":6,"description":125,"draft":126,"extension":127,"intro":128,"meta":129,"navId":130,"navigation":131,"ogImage":132,"path":133,"seo":134,"stem":135,"__hash__":136},"trust\u002Ftrust\u002Fsecurity.md","Security",{"type":7,"value":8,"toc":110},"minimark",[9,14,23,27,30,34,46,50,53,57,60,64,67,71,80,84,87,91,98,102],[10,11,13],"h2",{"id":12},"encryption-in-transit","Encryption in transit",[15,16,17,18,22],"p",{},"Every connection to 1410SMS is served over HTTPS\u002FTLS. That covers the school portal, the student and\nparent portals, and the mobile app. Subdomains (e.g. ",[19,20,21],"code",{},"yourschool.1410sms.com",") are covered by a wildcard\ncertificate, and custom domains are provisioned automatically through Cloudflare for SaaS, so a school\npointing its own domain at its portal gets a valid certificate without managing one itself.\nUnencrypted requests are not served.",[10,24,26],{"id":25},"password-security","Password security",[15,28,29],{},"Passwords are never stored in plain text. Every password, whether it belongs to a member of staff, a\nstudent or a parent, is stored using a one-way cryptographic hash. Not even we can read one back out\nof the database. Student accounts default to a system-generated password (their admission number) which we\nrecommend changing; staff and parent accounts always set their own.",[10,31,33],{"id":32},"role-based-permissions","Role-based permissions",[15,35,36,37,41,42,45],{},"Access is scoped to what an account actually needs. The platform recognises five distinct actor types\n(school admin, teacher, student, parent, and a short-lived guest identity for entrance-exam\ncandidates), each with its own permitted actions. Those permissions are enforced on every request\nrather than merely hidden in the interface.\nWithin a school, admin accounts can be tiered further: a ",[38,39,40],"strong",{},"primary"," admin can manage other admin\naccounts, while a ",[38,43,44],{},"regular"," admin has full teaching-feature access without the ability to create,\nedit, or deactivate other admins. A school can never lose its last primary admin by accident.",[10,47,49],{"id":48},"audit-logging","Audit logging",[15,51,52],{},"Sensitive actions are recorded in an audit log with the acting user, a timestamp and the originating\nIP address, so your school has a record of who did what and when. That covers administrative changes,\nsubscription overrides and support impersonation. Audit logs are visible to school admins from within the\ndashboard.",[10,54,56],{"id":55},"infrastructure-security","Infrastructure security",[15,58,59],{},"The platform runs on cloud infrastructure behind a managed edge network that terminates TLS and shields\nthe application from common network-level attacks. We do not publish detailed infrastructure diagrams\nor provider-specific configuration publicly, in line with standard practice. It is available to\nprospective enterprise customers under a mutual agreement where appropriate.",[10,61,63],{"id":62},"server-monitoring","Server monitoring",[15,65,66],{},"Application health is monitored continuously: database connectivity, background job queues and system\nresource usage, with automated error tracking on unhandled exceptions. The point is that we find out\nabout problems before a school has to tell us.",[10,68,70],{"id":69},"disaster-recovery","Disaster recovery",[15,72,73,74,79],{},"Recovery from an infrastructure failure is covered in detail on our\n",[75,76,78],"a",{"href":77},"\u002Ftrust\u002Fbackups-disaster-recovery","Backups & Disaster Recovery"," page.",[10,81,83],{"id":82},"security-updates","Security updates",[15,85,86],{},"Dependencies and the underlying platform are kept up to date, with security-relevant updates\nprioritised over routine ones. Schema and infrastructure changes go through a review step before\nrelease, and we favour reversible, incremental changes over large untested ones.",[10,88,90],{"id":89},"responsible-disclosure","Responsible disclosure",[15,92,93,94,97],{},"If you believe you've found a security vulnerability in 1410SMS, please tell us directly using the\n",[38,95,96],{},"Contact Security Team"," button below rather than disclosing it publicly. We don't yet run a formal\nbug bounty programme, but we investigate every report we receive and will acknowledge it. Please give\nus a reasonable opportunity to investigate and address an issue before sharing details with anyone\nelse.",[10,99,101],{"id":100},"planned-features","Planned features",[103,104,107],"callout",{"title":105,"tone":106},"On our roadmap","info",[15,108,109],{},"Two-Factor Authentication (2FA) for staff accounts, and a public status page for incident and\nmaintenance history. Neither exists yet. This section will be updated as they ship rather than\nadvertising them beforehand.",{"title":111,"searchDepth":112,"depth":112,"links":113},"",3,[114,116,117,118,119,120,121,122,123,124],{"id":12,"depth":115,"text":13},2,{"id":25,"depth":115,"text":26},{"id":32,"depth":115,"text":33},{"id":48,"depth":115,"text":49},{"id":55,"depth":115,"text":56},{"id":62,"depth":115,"text":63},{"id":69,"depth":115,"text":70},{"id":82,"depth":115,"text":83},{"id":89,"depth":115,"text":90},{"id":100,"depth":115,"text":101},"Encryption in transit, password security, role-based permissions, audit logging, server monitoring, and responsible disclosure at 1410SMS.",false,"md","How we protect access to the platform and the data inside it, in specific terms rather than marketing claims.",{},"security",true,null,"\u002Ftrust\u002Fsecurity",{"title":5,"description":125},"trust\u002Fsecurity","3m6UInCQjRsjKh8o_4aZAh6plYJED6lqa4q-77hRQKE",1785148428316]