Governance
Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.
How we protect school data, manage access and prepare for incidents. Schools can also request supporting documents for their own review.
Last updated 6 October 2026
Controls are applied according to risk, service scope and the evidence available for the current release.
Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.
Unique named administrative identities, school and role boundaries, least privilege, prompt revocation, MFA for Vero's privileged access and MFA that schools can turn on for their staff.
School-scoped authorisation and database row-level security are designed to prevent one school from accessing another school's records.
Provider-managed encryption at rest for hosted production data and recovery copies, with encrypted transport for data in transit.
Change review, dependency and secret scanning, automated tests, protected production credentials and risk-based remediation.
Security-relevant logging, monitoring, evidence preservation and maintained incident and data-breach response procedures.
All school and student data is stored and processed in Sydney, Australia: the Supabase application database, file storage and server functions, the Wonde synchronisation workload, Amazon SES email processing and encrypted AWS recovery copies. No student records or application data are stored or processed outside Australia. Limited technical metadata about web requests may be processed globally by infrastructure providers including Netlify and Cloudflare, as listed in the Privacy Policy.
See the provider and country scheduleVero combines managed-provider safeguards with documented recovery and data-lifecycle procedures.
Vero is not an emergency service. Schools should keep suitable manual continuity procedures for supervision and duty of care during an internet, provider or service interruption.
Please describe the issue, affected URL or component, likely impact and safe reproduction steps. Do not access another person's data, disrupt the service or run automated testing without written authorisation.
We will acknowledge the report and coordinate secure handling. Response timing depends on severity and the information supplied.