Trust
Security
Daymello holds safeguarding records for children and young people. Here's how we protect them.
Where the data lives
- The website runs from Vercel's London region. The database, file storage and sign-in service (Supabase) are in Supabase's Ireland (eu-west-1) region — in the EU, not yet in the UK. A move of those to Supabase's London region is planned; it has not happened yet.
- Encrypted at rest (AES-256). Encrypted in transit (TLS 1.3).
- Tenant isolation enforced at the database level via Postgres Row Level Security on every customer-scoped table.
- Daily backups. Point-in-time recovery on the Pro plan (RPO ≤ 1h, RTO ≤ 4h).
Access control
- Role-based access (admin, manager, DSL, senior, DPO, practitioner). Every change to who has access is audited.
- Two-step sign-in with an authenticator app is available to every user.
- 12-character minimum password. Lockout after 5 failed attempts in 10 minutes. Idle sessions end after 3 hours.
- Single sign-on (SAML) is not available yet. Talk to us if you need it.
Sub-processors
The full, current list is on our sub-processors page, including which ones apply to every organisation and which only run when you switch a feature on. Any change is notified to customers 30 days in advance with an objection window.
Certifications
- Cyber Essentials Plus — engagement in progress with an IASME-accredited assessor (target Q3 2026).
- ISO 27001 — under consideration post-Series A.
- Annual penetration test — booked.
Responsible disclosure
If you believe you've found a security vulnerability, please email security@aspireandthrive.co.uk. We respond to acknowledged reports within 2 working days. Please don't test against live customer tenants — use your own sandbox.
Compliance documents
- Terms of service
- Service level agreement
- DPIA, DPA template, KCSIE alignment statement available on request from privacy@aspireandthrive.co.uk.