Security Measures
Current design controls
Child Quest Codes are stored using password hashing for authentication, sessions use high-entropy tokens stored as hashes, parent accounts use WordPress authentication, school/parent access is permission checked, and the product minimises pupil identity data.
Before pilot
Complete hosting/subprocessor inventory, TLS and encryption review, backup/restore test, administrator access review, logging/monitoring review, vulnerability/update process, incident response contacts and a documented breach escalation process.
Access principle
Access should be least-privilege: school staff see their authorised school; linked grown-ups see linked children; sponsors receive no child profiles.
Contact
For data protection, privacy, safeguarding or online-safety questions about SchoolQuest, contact data@schoolquest.co.uk. Schools may use this address for data-rights requests, security concerns and safeguarding enquiries relating to the service.
SchoolQuest keeps these documents under review and will update the version and review date when material changes are made.
