Back to legal center

Security

A high-level overview of the safeguards and operational security principles that support the Sub platform.

Security posture

Sub is designed as an authenticated operational system for schools. We use layered safeguards intended to reduce misuse, protect accounts, and limit unauthorized access to school data.

Application controls

  • Role-based access paths for different workspace roles.
  • Session handling and login protections.
  • Request integrity controls such as CSRF protection on sensitive form flows.
  • Rate limiting and misuse-prevention controls on authentication and exposed routes.
  • Server-side validation and operational logging to support troubleshooting and incident review.

Operational practices

  • Least-privilege access where practical.
  • Change review before production updates.
  • Ongoing bug fixing and dependency maintenance as part of normal product operations.
  • Investigation and response when credible security issues are reported.

Customer responsibilities

  • Use strong passwords and protect credentials.
  • Assign access based on role and remove access promptly when staff leave or change responsibilities.
  • Avoid storing unnecessary personal information in free-text fields or uploads.
  • Notify us promptly if you suspect account compromise or an incident involving the service.

Reporting security concerns

To report a suspected vulnerability or security issue, email admin@infinitysolutions.app with a clear description, reproduction details where available, affected workspace information, and a safe contact method.