School documents · Pack 2026-08-29
Security measures (TOMs)
Technical and organisational measures for school due diligence.
- Who it is for
- DPOs, IT leads, MAT CISOs
- How to access it
- Public high-level description. Penetration-test reports and infrastructure diagrams are not published; request them under NDA if required.
This pack describes how Five Wells Education designs and operates the platform so schools can complete their own due diligence. It is not legal advice. The school remains the data controller for pupil and staff data it places in the product. A solicitor or DPO should review processing before go-live.
Application design
- Multi-tenant data model with school_id on primary records and row-level security for authenticated access.
- Cookie sessions via Supabase Auth. Passwords are handled by Supabase Auth, not custom hashes in application tables.
- Role-based access (pupil, parent, teacher, school admin, platform operator).
- Optional school-level staff MFA and optional passkeys. Platform operators can be required to use MFA.
Secrets and admin APIs
- Only the anonymous public key is used in the browser.
- Service-role use in runtime routes is limited to a documented set of school-admin operations (invites, certain student account repairs) after session checks.
- Staff PIN/QR flows are designed not to store plaintext PINs in application tables and not to log credential material.
Operations
- HTTPS in production.
- Rate limiting on authentication and sensitive staff endpoints when Redis (Upstash) is configured.
- School suspension can block a tenant.
- Support attachments are limited to small images; support mail is for signed-in users or an address the sender provides.
What this page is not
It is not a claim of ISO 27001 certification unless Five Wells separately states a current certificate. Ask for the latest assurance artefacts if your MAT requires them.
Related: All school documents · Roster field inventory
