Skip to main content
Trust

Security

How Project OWL protects accounts, data and the people who use it.

Account security

Sign-in uses a managed authentication provider with hashed credentials. Professional and school roles require manual approval before any restricted area unlocks.

Data access controls

Every database table is protected by row-level security so a signed-in user can only reach their own records. Administrative roles are stored separately from profile data so a profile edit can never grant privileges.

In transit and at rest

All traffic is served over HTTPS. Uploaded feedback attachments live in a private, write-once bucket that is not publicly listable.

Reporting a vulnerability

Email security@owl-protect.uk with steps to reproduce. Please do not test against other people’s accounts or data. We will acknowledge reports and fix confirmed issues as a priority.

What we ask of you

Use a unique passphrase and turn on two-factor authentication with your email provider. Project OWL will never ask you for a password, a one-time code, or a child’s login.