Teacher's Buddy

Information Security Policy

Last updated: 25 August 2026

Purpose

This policy establishes the information security requirements for Teacher's Buddy to protect the confidentiality, integrity, and availability of data entrusted to us by educators, schools, and publishers.

Data Classification

ClassificationDescriptionExamples
PublicInformation intended for public accessMarketing content, published resources
InternalInformation for team use onlyArchitecture docs, team communications
ConfidentialSensitive information requiring protectionUser PII, organisation data, API keys
RestrictedHighly sensitive informationProduction credentials, encryption keys

Access Control

  • All production systems require multi-factor authentication.
  • Access follows the principle of least privilege. Team members are granted the minimum permissions necessary for their role.
  • User-facing access is role-based at organisation and workspace levels (Owner, Admin, Member), enforced server-side.
  • System admin operations require WebAuthn/passkey MFA elevation.
  • Access reviews are conducted when team members join or leave.

Authentication

Teacher's Buddy uses passwordless authentication exclusively: OAuth (Google, Microsoft, Apple), magic links (15-minute expiry), and email OTP (6-digit, 10-minute expiry, 5 attempts max). No passwords are stored or transmitted.

Session tokens are generated using cryptographically secure mechanisms and are stored in HTTP-only cookies with appropriate SameSite and Secure settings in production. Sessions normally expire after 7 days, with refresh behaviour based on recent activity.

Encryption

  • In transit: Managed service endpoints use HTTPS/TLS. HSTS and other transport-security controls are applied according to the relevant application and hosting configuration.
  • At rest: Managed database, object-storage and hosting providers encrypt stored data where supported by the service configuration.
  • Inbound webhook authenticity is verified using provider-appropriate signing mechanisms, such as HMAC signatures.

Application Security

  • Schema validation and explicit authorisation checks are applied to relevant API boundaries.
  • User-controlled content is escaped, validated or sanitised according to its content type and rendering context.
  • Content-Security-Policy and related browser security headers are applied to relevant applications and routes and reviewed as the platform changes.
  • Risk-based rate limiting and anti-abuse controls protect authentication, generation and other sensitive endpoints.
  • Security-focused review is required for material application and infrastructure changes.
  • Internal security assessments, dependency scanning and vulnerability remediation are performed on a risk-based schedule.
  • Independent security testing is commissioned when required by risk, contractual commitments or an assurance program. We do not represent that a current independent penetration-test report exists unless we can provide it.

Infrastructure Security

  • Production applications run on managed infrastructure including Railway and Cloudflare, with other managed platforms used for specific administration or integration services.
  • Managed databases and storage services are protected through provider controls, scoped credentials and application-level access controls.
  • Private file access uses signed or authorised delivery mechanisms where supported by the relevant feature.
  • Security headers are configured according to the needs of each application; exceptions such as embedded content are reviewed rather than covered by a blanket policy.

Monitoring

  • Axiom for structured application logging and operational monitoring.
  • Sentry for application error monitoring where enabled.
  • PostHog for product analytics and diagnostic replay where enabled, with controls intended to limit unnecessary personal information.

Review

This policy is reviewed annually and updated in response to significant platform changes, security incidents, or changes in the threat landscape.

Contact

Questions about our security practices or reports of suspected vulnerabilities can be sent to security@teachersbuddy.com. Privacy questions can be sent to privacy@teachersbuddy.com.