Security is built into CentreFlow at every level. This document summarises the technical and organisational measures we have in place to protect the data entrusted to us by tuition centres.
1. Password Security
All CentreFlow user passwords are:
- Hashed using bcrypt with a minimum work factor of 10, making brute-force attacks computationally infeasible
- Never stored in plain text at any point in the system
- Subject to minimum complexity requirements: at least 8 characters, one uppercase letter, one number
- Replaceable at any time by account holders or administrators
- Subject to forced reset on first login where accounts are created by a manager
2. Role-Based Access Control
CentreFlow enforces strict role-based access:
- Managers have full access to their centre's data including students, payments, reports, and settings
- Staff have access limited to register and attendance functions — they cannot access payment data, analytics, or sensitive compliance records
- Platform administrators can manage centre accounts but operate under audit logging
All access decisions are validated server-side on every request — client-side role restrictions alone are never relied upon.
3. Centre Data Isolation
Each tuition centre's data is logically isolated. It is not possible for one centre's staff or managers to access another centre's student, payment, or operational data. Every data query is filtered by centre ID at the application layer.
4. Encrypted Transmission
All data transmitted between your browser or device and CentreFlow servers is encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS. We do not allow unencrypted access to the platform.
5. Session Security
- Sessions are time-limited and validated server-side on each request
- Sessions expire after a period of inactivity (typically 8 hours)
- Logging out immediately invalidates the session server-side
- Session tokens are stored in browser session storage (not persistent cookies) where applicable
6. Audit Logging
CentreFlow maintains audit logs for significant user actions including:
- User creation, modification, and deletion
- Login events and session activity
- Password resets and changes
- Centre configuration changes
- GoCardless payment actions
Audit logs are retained for at least 12 months and are accessible to platform administrators for incident investigation.
7. Least Privilege Access
Internal access to CentreFlow infrastructure follows the principle of least privilege. Only personnel who require access to perform their duties are granted it, and access is reviewed regularly. Production data access is restricted and audited.
8. Backups and Recovery
Data is backed up regularly to ensure business continuity in the event of a failure. Backups are encrypted, stored separately from the primary data store, and tested periodically. Our target recovery time objective (RTO) is 4 hours for critical systems.
9. Vulnerability Management
We apply security patches to our infrastructure and dependencies in a timely manner. We conduct periodic reviews of our platform's security posture and act promptly on identified vulnerabilities.
10. Incident Response
In the event of a security incident:
- We will identify and contain the incident as rapidly as possible
- Affected controllers will be notified within 72 hours where personal data may have been affected
- A root cause analysis will be conducted and remediation steps implemented
- We will cooperate fully with affected centres and, where required, with the ICO
To report a security concern: security@centreflow.co.uk