Security at Vero

How we protect school data, manage access and prepare for incidents. Schools can also request supporting documents for their own review.

Last updated 6 October 2026

Core security controls

Controls are applied according to risk, service scope and the evidence available for the current release.

Governance

Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.

Identity and access

Unique named administrative identities, school and role boundaries, least privilege, prompt revocation, MFA for Vero's privileged access and MFA that schools can turn on for their staff.

Tenant separation

School-scoped authorisation and database row-level security are designed to prevent one school from accessing another school's records.

Encryption

Provider-managed encryption at rest for hosted production data and recovery copies, with encrypted transport for data in transit.

Secure development

Change review, dependency and secret scanning, automated tests, protected production credentials and risk-based remediation.

Logging and response

Security-relevant logging, monitoring, evidence preservation and maintained incident and data-breach response procedures.

Hosting and geography

Where Vero stores and processes data

All school and student data is stored and processed in Sydney, Australia: the Supabase application database, file storage and server functions, the Wonde synchronisation workload, Amazon SES email processing and encrypted AWS recovery copies. No student records or application data are stored or processed outside Australia. Limited technical metadata about web requests may be processed globally by infrastructure providers including Netlify and Cloudflare, as listed in the Privacy Policy.

See the provider and country schedule
School dataHosted in Sydney, Australia
Student GPSNot collected

Resilience and lifecycle

Vero combines managed-provider safeguards with documented recovery and data-lifecycle procedures.

Recovery

  • Encrypted managed backups and access-restricted recovery copies
  • At least 90 days of Database, Auth, Storage and configuration recovery coverage
  • Production-equivalent restore exercised on 9 August 2026

Data lifecycle

  • Reusable school export available through an authorised request
  • Active records targeted for deletion within 30 days of a validated request
  • Recovery copies generally age out 90 days after capture or release; see details

Vero is not an emergency service. Schools should keep suitable manual continuity procedures for supervision and duty of care during an internet, provider or service interruption.

Responsible disclosure

Report a potential security issue.

Please describe the issue, affected URL or component, likely impact and safe reproduction steps. Do not access another person's data, disrupt the service or run automated testing without written authorisation.

Email [email protected]

We will acknowledge the report and coordinate secure handling. Response timing depends on severity and the information supplied.