All documents

Security and Breach Policy

A public summary of implemented safeguards and the incident-response approach.

Version:
2026-08-14-v1
Effective August 15, 2026
Effective August 15, 2026

This is the controlling English (United States) version. The en-US text controls if a convenience translation differs.

1. Security approach

Desk Dollars uses proportionate safeguards for a classroom application and reviews controls as the service changes. No internet service can eliminate risk, and this summary describes implemented practices rather than a certification or guarantee.

2. Application and identity controls

Passwords are hashed; app sessions are signed and idle-limited for students. Server-side authorization distinguishes owner, teacher, and student routes; teacher access is scoped by class ownership and student access by enrollment. Same-origin guards, schema validation, rate limits, security headers, login throttling, and no-secret QR payloads reduce common abuse paths.

Balance changes go through a ledger service and transactions remain immutable; corrections, adjustments, and refunds preserve history. Student pages show first name and last initial only, no classmate balances, and no leaderboards.

3. Infrastructure, transport, secrets, and backups

Public production requires HTTPS. Secrets are supplied outside Git through deployment configuration, sensitive account-email payloads use an application encryption key, and logs are minimized. Configured backup, hosting, email, monitoring, and support vendors must be disclosed before they receive production personal data.

Backups support recovery but are not an uninterrupted-service or complete-restoration guarantee. Restore procedures must preserve deletion state and immutable-history safeguards.

4. Incident response

Andrew Hall owns incident coordination. The internal runbook covers detection and triage, containment, evidence preservation, vendor coordination, scope and legal assessment, session and credential revocation, restoration, communication, and post-incident review.

If a confirmed incident affects personal data, Desk Dollars coordinates with affected schools/teachers and vendors and gives notices required by applicable law or contract. Content and timing are jurisdiction-specific; this policy does not promise one global deadline.

5. Reporting and contact

Report a suspected vulnerability or security event to [email protected] with steps, affected URL, and impact, but do not access other users' data or disrupt the service. Do not include passwords, tokens, student records, or exploit data beyond what is necessary to explain the issue.

6. Policy boundaries

This page does not represent that every regional security law applies, promise a response or recovery objective, or activate an unconfigured vendor or transfer safeguard. The en-US text controls.

Security and Breach Policy | Desk Dollars | Desk Dollars