DRIVESIGHT / security

Security and access controls.

Security architecture that supports trust. These are implementation details, not certification claims.

Separate school workspaces

Server-derived tenant context scopes school-owned records, reports and queries. Role-based permissions limit what accounts can do. Platform operators see aggregate school health rather than lesson routes or student details.

Traceable evidence

Route points, device events, audit events and reconciliation snapshots are append-only at the database level. Authorised corrections leave a reason and a recorded history. No system is described here as completely tamper-proof.

Sessions and transport

The platform includes rotating device refresh tokens, reuse detection, lockout controls, input validation, rate limiting and field encryption support. Production mobile apps require HTTPS. Deployment configuration and secret management are part of release readiness.

Report a concern

Send security questions to [email protected]. Do not include passwords, access tokens or sensitive student records in the initial email. The team can agree a suitable channel for details.

Let’s talk about your school