Security
Current controls, plainly stated.
This page describes the deployed architecture and operating posture. It is not a SOC 2, ISO 27001, penetration-test, or regulatory certification.
Architecture and access
- TLS protects browser and API traffic in transit.
- Primary application data and object storage use Supabase; the current project’s primary region is Singapore (
ap-southeast-1). - Netlify hosts the public site and serverless functions. Service credentials remain server-side.
- Authenticated data paths apply user or service-role checks, and database row-level security is used where implemented. A verified school-program role boundary is still a production gate.
- Administrative access is limited to authorized Vindica personnel. Authorized access may occur from South Korea.
Application controls
- Short-lived or revocable authorization is used for connected services.
- Leaked-password protection is enabled: account passwords found in known breach lists are rejected.
- Google Classroom and Gmail permissions are read-only and opt-in; Gmail disconnect revokes access and scrubs connection state.
- Requests are rate-limited on protected surfaces, and security-relevant operations produce audit records where implemented.
- The deployment build publishes an explicit allowlist of public pages and browser assets, not the repository root.
Known work before a K–12 production pilot: complete the live database function-permission review, demonstrate comprehensive deletion in a disposable environment, establish incident-response ownership and notification terms, and complete independent legal/security review.
Incident reporting
Report a suspected security or privacy incident to kevinchoi@vindicaseneca.com. Include the affected URL, approximate time, and steps to reproduce; do not email student data, passwords, API keys, or exploit payloads containing live records.
Verification available to a school
Before a production pilot, Vindica can provide a scoped architecture diagram, data-field schedule, subprocessor list, access review, migration record, test results, and deletion rehearsal. Evidence is shared under appropriate confidentiality; it should be evaluated by the school rather than treated as a blanket assurance.