Governance
Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.
The controls Vero operates today, the assurance work still in progress, and the supporting material available to an authorised school review.
Controls are applied according to risk, service scope and the evidence available for the current release.
Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.
Unique named administrative identities, school and role boundaries, least privilege, prompt revocation and MFA for privileged provider access where supported.
School-scoped authorisation and database row-level security are designed to prevent one school from accessing another school's records.
Provider-managed encryption at rest for hosted production data and recovery copies, with encrypted transport for data in transit.
Change review, dependency and secret scanning, automated tests, protected production credentials and risk-based remediation.
Security-relevant logging, monitoring, evidence preservation and maintained incident and data-breach response procedures.
The primary Supabase application database and the configured Wonde synchronisation workload are in Sydney, Australia, with encrypted AWS backups also hosted in Australia. Netlify and Cloudflare edge networks and Resend email services may process limited website, security and email information overseas, as listed in the Privacy Policy.
See the provider and country scheduleVero combines managed-provider safeguards with documented recovery and data-lifecycle procedures.
Vero is not an emergency service. Schools should keep suitable manual continuity procedures for supervision and duty of care during an internet, provider or service interruption.
Vero separates an implemented control from the evidence required to prove that it operates.
| Area | Current public position | Status |
|---|---|---|
| ST4S | Tier 1 readiness is being prepared against the assigned ST4S readiness form, with v2026.1 used as the current conservative gap framework. Vero has not yet completed an ST4S assessment. | In progress |
| South Australia | A Department/Wonde cyber-security profile and evidence mapping are prepared for review. This does not mean the Department has approved Vero. | Review material ready |
| ISO 27001 / SOC 2 / IRAP | Vero is not independently certified, attested or accredited to these schemes. Relevant hosting-provider reports may be supplied where disclosure rights allow. | Not held |
| Vulnerability assessment | Local and repository controls are operating. The current hosted monthly scan and triage artefact for every assessed application is still being completed and is not represented as finished. | Evidence pending |
| Independent testing | A current production-equivalent independent application security and WCAG 2.2 AA report is not yet retained. | Evidence pending |
Please describe the issue, affected URL or component, likely impact and safe reproduction steps. Do not access another person's data, disrupt the service or run automated testing without written authorisation.
We will acknowledge the report and coordinate secure handling. Response timing depends on severity and the information supplied.