Trust Centre / Security overview
Security overviewHow we protect your records.
What is in place today to keep accounts, children’s records and school data safe, and what still has to happen before launch. Everything here describes how Ponder works now.
Hosting and data location
Ponder’s database, private file storage and sign-in service are hosted by Supabase in Sydney, Australia. Ponder’s server functions, which talk to the AI, voice, email and payment providers, run on Vercel in Sydney. A few providers process limited information outside Australia; they are listed on the service providers page.
Who can see what
- Rules in the database, not just the screen. Every table that holds personal information uses row-level security, so the database itself decides who can see or change each record.
- Families and schools are kept apart. A family’s records are visible to that family’s guardians; a school’s records to that school’s staff; and teachers see only their own classes. A parent links a child to a school only by accepting the school’s invitation.
- Tested. Automated multi-user checks sign in as each kind of user and confirm that one family or school can’t see another’s records.
- Admin rights are checked by the database. Being a Ponder admin gives access to test tools and school verification, not to families’ or schools’ learning records.
Accounts and sign-in
- Adults sign in with Google or with an email address and password. Passwords are stored only as secure hashes by our sign-in provider; Ponder never sees them.
- Children never have an email address or password. A parent or carer sets up a child’s device with a one-time code that expires after 15 minutes, and can sign that device out at any time.
- Ponder verifies each school before school features open.
Encryption
All traffic to Ponder uses HTTPS, and browsers are told to use only HTTPS for the site and its subdomains (HTTP Strict Transport Security, for two years). Our hosting providers encrypt stored data at rest [to be confirmed against provider documentation].
Protections in the service
- Keys stay on the server. Keys for the AI, voice, email and payment services are kept in server settings and never sent to browsers.
- AI only for signed-in accounts. Ponder’s AI and speech features serve only signed-in people, and requests from other websites are refused.
- Limits. Sign-in, AI, messaging and other features are rate-limited, and AI use has per-learner and whole-service limits, with a switch that turns every AI feature off at once if needed.
- Browser protections. Every page is served with a strict content security policy, is blocked from being framed by other sites, and denies camera and location access; the microphone is available only to Ponder itself, for spoken questions.
- Private files. Files are kept in private storage with the same access rules as the database, and are never public.
Payments
Payments will be processed by Stripe. Card details go directly to Stripe; Ponder never receives or stores card numbers. Payments are switched off today.
Audit log and deletion
Adding, changing or deleting results, learning plans and report cards is recorded in an audit log (who, what and when, without copying grades or comments), which a school’s owners and admins can see for their school. A daily job deletes records when their retention period ends, as set out in the retention section of the Privacy Policy. Account holders can download or delete their data from My account.
Before launch
Still to do: an independent security assessment; verified backups with a tested restore; a written and exercised incident response plan, including how we would notify schools, families and the Office of the Australian Information Commissioner of an eligible data breach; confirmed multi-factor authentication for everyone who operates Ponder; and an accessibility review.
Ponder does not claim ISO 27001, SOC 2 or any other security certification.
Report a security concern
If you think you have found a security problem in Ponder, please email hello@ponderlearning.com with the details [dedicated security contact to be set up]. Please don’t access other people’s records or disrupt the service while testing. If you think your own account has been compromised, change your password and contact us straight away.