Trust

Security and trust

These are the working policies behind School Hub Club. They are reviewed at least once a year, and last reviewed on 9 September 2026. Director Douglas Tracey is accountable for security decisions.

Not yet independently certified

School Hub Club is not yet SOC 2 or ISO 27001 certified or accredited. The controls below are implemented to align with those frameworks and form the basis for future certification. They describe how we work today, not a guarantee of audit completion.

Information security

  • All data is encrypted in transit and at rest by our hosting provider.
  • Strong authentication protects family accounts, and two-factor authentication is required or encouraged depending on account configuration.
  • Each family's records are separated at the database level, so no family can read another's data.
  • Uploaded files are restricted to the school they belong to and the parents of children at that school.
  • Automated security checks run against the database and dependencies; findings are tracked and fixed before release where practicable.

Access control

  • Access is granted on a least-privilege basis and tied to a named person.
  • School staff can only manage schools they have been approved for.
  • Platform administrator access is limited to named directors, and their access is recorded.
  • Access rights are reviewed regularly and removed promptly when someone leaves.
  • Shared accounts and shared passwords are not permitted.

Incident response

  • Suspected incidents are reported to support@schoolhub.club and triaged within one working day.
  • Confirmed personal data breaches are reported to the ICO within 72 hours of discovery.
  • Affected families are told directly where there is a high risk to them.
  • Every incident is written up with cause, actions taken and preventative changes.

Change management

  • All changes are version controlled and reviewed before release.
  • Database changes are applied through recorded migrations only.
  • Changes are tested against a preview environment before going live.
  • Releases can be rolled back if a fault is found.

Backup and recovery

  • The database is backed up automatically by our hosting provider with point-in-time recovery.
  • Restore testing is carried out as part of our ongoing security programme.
  • Our target recovery objectives are to restore service promptly and lose as little data as possible; exact targets depend on the hosting provider's capabilities and our restore testing.

Supplier management

  • We use Supabase (database, files, sign-in), Cloudflare (hosting), Stripe (payments), Resend (email) and Google Analytics (optional measurement).
  • New suppliers are assessed for security and data protection before use.
  • Supplier security posture is reviewed regularly.

Data retention

  • Active accounts are kept while in use; unfinished trials are removed 90 days after the trial ends.
  • Cancelled accounts are removed within 30 days.
  • Billing records are kept for 6 years; security logs for 12 months.
  • Families can delete everything themselves at any time from Settings.

Risk register (summary)

  • Unauthorised access to family data — mitigated by two-factor authentication, per-family separation and logging.
  • Supplier outage or failure — mitigated by managed hosting with backups and documented recovery targets.
  • Inaccurate school information — mitigated by review-before-publish and full change history.
  • Loss of key person knowledge — mitigated by written policies and documented systems.

Compliance roadmap

  • Maintain the security controls above and review them at least annually.
  • Complete a formal risk assessment and document it.
  • Engage an independent auditor to evaluate SOC 2 Type II and/or ISO 27001 suitability.
  • Publish the resulting certification or attestation once achieved.

We are not yet certified or accredited to SOC 2 or ISO 27001; these policies describe how we work today and form the basis for future certification. To report a security concern, please contact us.