Information Security Policy
Last updated: 25 August 2026
Purpose
This policy establishes the information security requirements for Teacher's Buddy to protect the confidentiality, integrity, and availability of data entrusted to us by educators, schools, and publishers.
Data Classification
| Classification | Description | Examples |
|---|---|---|
| Public | Information intended for public access | Marketing content, published resources |
| Internal | Information for team use only | Architecture docs, team communications |
| Confidential | Sensitive information requiring protection | User PII, organisation data, API keys |
| Restricted | Highly sensitive information | Production credentials, encryption keys |
Access Control
- All production systems require multi-factor authentication.
- Access follows the principle of least privilege. Team members are granted the minimum permissions necessary for their role.
- User-facing access is role-based at organisation and workspace levels (Owner, Admin, Member), enforced server-side.
- System admin operations require WebAuthn/passkey MFA elevation.
- Access reviews are conducted when team members join or leave.
Authentication
Teacher's Buddy uses passwordless authentication exclusively: OAuth (Google, Microsoft, Apple), magic links (15-minute expiry), and email OTP (6-digit, 10-minute expiry, 5 attempts max). No passwords are stored or transmitted.
Session tokens are generated using cryptographically secure mechanisms and are stored in HTTP-only cookies with appropriate SameSite and Secure settings in production. Sessions normally expire after 7 days, with refresh behaviour based on recent activity.
Encryption
- In transit: Managed service endpoints use HTTPS/TLS. HSTS and other transport-security controls are applied according to the relevant application and hosting configuration.
- At rest: Managed database, object-storage and hosting providers encrypt stored data where supported by the service configuration.
- Inbound webhook authenticity is verified using provider-appropriate signing mechanisms, such as HMAC signatures.
Application Security
- Schema validation and explicit authorisation checks are applied to relevant API boundaries.
- User-controlled content is escaped, validated or sanitised according to its content type and rendering context.
- Content-Security-Policy and related browser security headers are applied to relevant applications and routes and reviewed as the platform changes.
- Risk-based rate limiting and anti-abuse controls protect authentication, generation and other sensitive endpoints.
- Security-focused review is required for material application and infrastructure changes.
- Internal security assessments, dependency scanning and vulnerability remediation are performed on a risk-based schedule.
- Independent security testing is commissioned when required by risk, contractual commitments or an assurance program. We do not represent that a current independent penetration-test report exists unless we can provide it.
Infrastructure Security
- Production applications run on managed infrastructure including Railway and Cloudflare, with other managed platforms used for specific administration or integration services.
- Managed databases and storage services are protected through provider controls, scoped credentials and application-level access controls.
- Private file access uses signed or authorised delivery mechanisms where supported by the relevant feature.
- Security headers are configured according to the needs of each application; exceptions such as embedded content are reviewed rather than covered by a blanket policy.
Monitoring
- Axiom for structured application logging and operational monitoring.
- Sentry for application error monitoring where enabled.
- PostHog for product analytics and diagnostic replay where enabled, with controls intended to limit unnecessary personal information.
Review
This policy is reviewed annually and updated in response to significant platform changes, security incidents, or changes in the threat landscape.
Contact
Questions about our security practices or reports of suspected vulnerabilities can be sent to security@teachersbuddy.com. Privacy questions can be sent to privacy@teachersbuddy.com.