Legal

Security

How workspaces are separated, how access is controlled, and how to report a vulnerability to us.

Last updated 12 August 2026

Workspace separation

Every record belongs to an organisation, and access is enforced at the database level with row-level security. A request can only return rows belonging to a workspace the signed-in user is a member of.

Access control

  • Roles are defined by the workspace owner, module by module, from no access through to full access.
  • Sensitive actions can require approval from the owner or the person's line manager.
  • Individual overrides let an owner tighten or widen access for one person.
  • Navigation, routes and in-page actions all follow the permissions in force.

Integration credentials

Keys you add for payment, messaging, AI or accounting providers are stored encrypted and scoped to your workspace. They are not exposed to the browser and are used server-side only when carrying out an action you triggered.

Reporting a vulnerability

If you believe you have found a security issue, email security@eduthropy.com with enough detail to reproduce it. Please give us a reasonable window to respond before disclosing publicly, and avoid accessing data that is not yours while testing.

Questions about this page?

Write to Eduthropy Impact Technologies Ltd at hello@eduthropy.com and we will respond in writing.