Security
How Project OWL protects accounts, data and the people who use it.
Account security
Sign-in uses a managed authentication provider with hashed credentials. Professional and school roles require manual approval before any restricted area unlocks.
Data access controls
Every database table is protected by row-level security so a signed-in user can only reach their own records. Administrative roles are stored separately from profile data so a profile edit can never grant privileges.
In transit and at rest
All traffic is served over HTTPS. Uploaded feedback attachments live in a private, write-once bucket that is not publicly listable.
Reporting a vulnerability
Email security@owl-protect.uk with steps to reproduce. Please do not test against other people’s accounts or data. We will acknowledge reports and fix confirmed issues as a priority.
What we ask of you
Use a unique passphrase and turn on two-factor authentication with your email provider. Project OWL will never ask you for a password, a one-time code, or a child’s login.

