How we protect your data
A driving school's records hold minors' details, addresses and payment history. Here is what we actually do about that, and what we do not yet claim.
What we do today
Encrypted in transit
Every request between your browser and the platform runs over TLS. There is no unencrypted path into the system.
Encrypted at rest
Records are stored by our database provider with encryption at rest, on managed infrastructure we do not operate ourselves.
Role-based access
School admins, instructors, students and parents each see only their own scope. Roles and permissions are managed from a settings screen, not by support request.
Separated by school
Every record is bound to a school, and access is checked against your membership on the server for each request rather than hidden in the interface.
Who else handles your data
We keep the list short and name it plainly, because a subprocessor you did not know about is a security problem of its own.
- Identity and sign-in
- Clerk
- Application database
- Convex
- Transactional email
- Resend
Your data stays yours
You own everything you put into the platform. You can access it, correct it, export it and ask us to delete it — the privacy policy sets out how.
Read the privacy policyWhat we do not claim
We do not hold SOC 2, ISO 27001 or PCI DSS certification, and we do not publish an uptime SLA. Plenty of platforms our size imply otherwise; we would rather you find out here than during procurement. If that changes, this page will say so and name the auditor.
Report a vulnerability
If you have found a security issue, tell us before you tell anyone else and we will work it through with you.
Contact us