How it's kept safe.
No numbers here that aren't true, and no numbers we haven't measured yet. This is what is actually in place today, and what we are still waiting to publish honestly.
Nine things, built in and checked.
Security is not a page of promises separate from the product. Each of these is part of how the platform runs, not a setting a club has to go and find.
Your data stays in the UK
Club data lives in Supabase's eu-west-2 region, London, and the functions that serve it are pinned to the same region on Vercel. Nothing routes through a data centre outside the UK by default.
Encrypted in transit and at rest
Every connection to the platform runs over TLS, and the database encrypts data at rest. There is no plain-text path between a browser and a club's records.
Multi-factor authentication, mandatory for admins
Every club admin account requires MFA to sign in. It is not a setting a club can leave switched off, because an admin login reaches children's data.
Backed up and recoverable
Point-in-time recovery plus 30 days of backups, so a mistake or an outage is something we restore from, not something a club loses for good.
A published list of who else touches your data
Every sub-processor we use is named in the data processing terms, so a club can see exactly who else the data passes through and why.
Access on a need-to-know basis, every sensitive read logged
Role-scoped access decides what a person can see, and a look at sensitive data, safeguarding and medical records included, is logged, including when it is our own staff looking.
Built around the rules for children's data
Consent, retention and who can see what for under-18s are enforced in the platform itself, not left to a policy nobody reads. The detail is on the safeguarding page.
Tested before launch, and every year after
The platform gets an independent penetration test before it goes live, and again every year after that, not a one-off box tick.
A proper place to report a problem
Found a security issue? Email security@thefullsquad.com. There is also a standard security.txt at /.well-known/security.txt for anyone whose tooling looks for one first.
The two numbers we won't guess at.
Recovery time and recovery point objectives, and our breach notification target, will be published here once our restore test has run. We would rather say nothing than publish a number we haven't actually measured.
Service status: status.thefullsquad.com (coming).
How we handle data as your processor is set out in full in the data processing terms, and how we protect children specifically is on the safeguarding page.
Built the careful way.
Security is treated the same way as safeguarding here: built in from the start, not bolted on before launch. Leave an email and you'll see it take shape, and get first pick of a place when it opens.
