Trust
Security and trust
These are the working policies behind School Hub Club. They are reviewed at least once a year, and last reviewed on 9 September 2026. Director Douglas Tracey is accountable for security decisions.
Not yet independently certified
School Hub Club is not yet SOC 2 or ISO 27001 certified or accredited. The controls below are implemented to align with those frameworks and form the basis for future certification. They describe how we work today, not a guarantee of audit completion.
Information security
- All data is encrypted in transit and at rest by our hosting provider.
- Strong authentication protects family accounts, and two-factor authentication is required or encouraged depending on account configuration.
- Each family's records are separated at the database level, so no family can read another's data.
- Uploaded files are restricted to the school they belong to and the parents of children at that school.
- Automated security checks run against the database and dependencies; findings are tracked and fixed before release where practicable.
Access control
- Access is granted on a least-privilege basis and tied to a named person.
- School staff can only manage schools they have been approved for.
- Platform administrator access is limited to named directors, and their access is recorded.
- Access rights are reviewed regularly and removed promptly when someone leaves.
- Shared accounts and shared passwords are not permitted.
Incident response
- Suspected incidents are reported to support@schoolhub.club and triaged within one working day.
- Confirmed personal data breaches are reported to the ICO within 72 hours of discovery.
- Affected families are told directly where there is a high risk to them.
- Every incident is written up with cause, actions taken and preventative changes.
Change management
- All changes are version controlled and reviewed before release.
- Database changes are applied through recorded migrations only.
- Changes are tested against a preview environment before going live.
- Releases can be rolled back if a fault is found.
Backup and recovery
- The database is backed up automatically by our hosting provider with point-in-time recovery.
- Restore testing is carried out as part of our ongoing security programme.
- Our target recovery objectives are to restore service promptly and lose as little data as possible; exact targets depend on the hosting provider's capabilities and our restore testing.
Supplier management
- We use Supabase (database, files, sign-in), Cloudflare (hosting), Stripe (payments), Resend (email) and Google Analytics (optional measurement).
- New suppliers are assessed for security and data protection before use.
- Supplier security posture is reviewed regularly.
Data retention
- Active accounts are kept while in use; unfinished trials are removed 90 days after the trial ends.
- Cancelled accounts are removed within 30 days.
- Billing records are kept for 6 years; security logs for 12 months.
- Families can delete everything themselves at any time from Settings.
Risk register (summary)
- Unauthorised access to family data — mitigated by two-factor authentication, per-family separation and logging.
- Supplier outage or failure — mitigated by managed hosting with backups and documented recovery targets.
- Inaccurate school information — mitigated by review-before-publish and full change history.
- Loss of key person knowledge — mitigated by written policies and documented systems.
Compliance roadmap
- Maintain the security controls above and review them at least annually.
- Complete a formal risk assessment and document it.
- Engage an independent auditor to evaluate SOC 2 Type II and/or ISO 27001 suitability.
- Publish the resulting certification or attestation once achieved.
We are not yet certified or accredited to SOC 2 or ISO 27001; these policies describe how we work today and form the basis for future certification. To report a security concern, please contact us.
