Public overview · reviewed 11 August 2026

Security, stated precisely.

The controls Vero operates today, the assurance work still in progress, and the supporting material available to an authorised school review.

Core security controls

Controls are applied according to risk, service scope and the evidence available for the current release.

Governance

Named security, privacy and incident ownership; controlled policies, registers, risk reviews and documented exceptions.

Identity and access

Unique named administrative identities, school and role boundaries, least privilege, prompt revocation and MFA for privileged provider access where supported.

Tenant separation

School-scoped authorisation and database row-level security are designed to prevent one school from accessing another school's records.

Encryption

Provider-managed encryption at rest for hosted production data and recovery copies, with encrypted transport for data in transit.

Secure development

Change review, dependency and secret scanning, automated tests, protected production credentials and risk-based remediation.

Logging and response

Security-relevant logging, monitoring, evidence preservation and maintained incident and data-breach response procedures.

Hosting and geography

Sydney is the primary region—not the whole processing story.

The primary Supabase application database and the configured Wonde synchronisation workload are in Sydney, Australia, with encrypted AWS backups also hosted in Australia. Netlify and Cloudflare edge networks and Resend email services may process limited website, security and email information overseas, as listed in the Privacy Policy.

See the provider and country schedule
Primary databaseSydney, Australia
Wonde workerConfigured for Sydney
Supporting processingAustralia, US, UK and other provider-listed locations
Student GPSNot collected

Resilience and lifecycle

Vero combines managed-provider safeguards with documented recovery and data-lifecycle procedures.

Recovery

  • Encrypted managed backups and access-restricted recovery copies
  • 90-day immutable Database, Auth, Storage and configuration recovery set
  • Production-equivalent restore exercised on 9 August 2026

Data lifecycle

  • Reusable school export available through an authorised request
  • Active-system deletion targeted within 30 days after validated instruction
  • Recoverable copies expire within 90 days, subject to lawful hold or agreed records obligations

Vero is not an emergency service. Schools should keep suitable manual continuity procedures for supervision and duty of care during an internet, provider or service interruption.

Assurance status

Vero separates an implemented control from the evidence required to prove that it operates.

AreaCurrent public positionStatus
ST4STier 1 readiness is being prepared against the assigned ST4S readiness form, with v2026.1 used as the current conservative gap framework. Vero has not yet completed an ST4S assessment.In progress
South AustraliaA Department/Wonde cyber-security profile and evidence mapping are prepared for review. This does not mean the Department has approved Vero.Review material ready
ISO 27001 / SOC 2 / IRAPVero is not independently certified, attested or accredited to these schemes. Relevant hosting-provider reports may be supplied where disclosure rights allow.Not held
Vulnerability assessmentLocal and repository controls are operating. The current hosted monthly scan and triage artefact for every assessed application is still being completed and is not represented as finished.Evidence pending
Independent testingA current production-equivalent independent application security and WCAG 2.2 AA report is not yet retained.Evidence pending
Responsible disclosure

Report a potential security issue.

Please describe the issue, affected URL or component, likely impact and safe reproduction steps. Do not access another person's data, disrupt the service or run automated testing without written authorisation.

Email support@vero.education

We will acknowledge the report and coordinate secure handling. Response timing depends on severity and the information supplied.