Trust & Security

    Your organisation's records should stay governed.

    Eduthropy is designed around organisation separation, permissions, server-authoritative access controls and transparent AI behaviour.

    This page describes how the product works today. It does not claim certifications Eduthropy does not hold.

    Organisation separation

    Every record belongs to an organisation, and access is enforced at the database level with row-level security. A request can only ever return rows belonging to a workspace the signed-in user is a member of. Separation is not done by hiding buttons in the interface.

    Roles and permissions

    • Roles (owner, admin, manager, member) are defined by the workspace owner, module by module, from no access through to full access.
    • Sensitive actions can require approval from the owner or the person's line manager.
    • Individual overrides let an owner tighten or widen access for one person.
    • Granular per-person permission overrides are available on the Scale plan. Standard roles apply on every plan.
    • Navigation, routes and in-page actions all follow the permissions in force.

    Plan and permission are separate

    What your plan includes and what a person is allowed to do are two different checks. Organisation type decides which modules are relevant, the plan decides which capabilities are available, and permissions decide who can act. A capability that your plan does not include is never presented as a permission error.

    Server-authoritative enforcement

    Plan and permission checks run on the server before any durable write, paid call or AI request. The client interface reflects the same rules, but the server is the authority. A request that the interface would not offer is still refused if it reaches the server.

    Integration credentials

    Keys you add for payment, messaging, AI or accounting providers are stored encrypted and scoped to your workspace. They are not exposed to the browser and are used server-side only when carrying out an action you triggered. You can disconnect an integration at any time without touching your records.

    Subscription payments

    Subscription payments are handled by Stripe. Card details are entered in Stripe Checkout, not in Eduthropy. Promotion codes are entered and validated by Stripe; a discount changes the billed amount only and does not affect your plan, included people, storage, capabilities or trial.

    AI behaviour

    Where Eduthropy Intelligence is enabled (Growth and Scale), AI is used to explain figures that Eduthropy has already calculated, grounded in your recorded data with the evidence shown. It does not determine your figures, predict outcomes, infer relationships you have not recorded, or act on its own. You can use Eduthropy-managed AI, bring your own OpenAI or Anthropic key, or turn AI off.

    Non-destructive downgrade

    Changing to a lower plan never deletes your organisational records. Records that belong to a higher tier are retained and can remain available to read; creating or editing them is what pauses until you are back on a plan that includes the capability.

    Getting your data out

    Finance data exports to Xero, QuickBooks or CSV files, and documents and generated PDFs can be downloaded at any time.

    Reporting a vulnerability

    If you believe you have found a security issue, email security@eduthropy.com with enough detail to reproduce it. Please give us a reasonable window to respond before disclosing publicly, and avoid accessing data that is not yours while testing.

    The legal documents

    This page is an overview, not a contract. The privacy notice, terms of service and cookie notice are the governing text.

    Governed by design, not by trust alone.