Skip to content
IdeaScore
Security

Security practices, stated plainly

What we do today, in plain terms. No certifications are claimed.

Access control

Who can see and change what

  • Five roles

    Platform admin, organisation owner, programme admin, evaluator and applicant, each scoped to what that role needs to see.

  • Organisation isolation

    Every organisation's data is isolated within a multi-tenant database; no organisation can query another's records.

  • Session lockout

    Repeated failed sign-in attempts lock the account temporarily, to slow down credential-guessing.

  • Re-authentication for sensitive edits

    Changes such as altering a submitted score or removing a user require the acting user to re-enter their password.

Data protection

How data is stored and moved

  • TLS in transit

    All traffic between a browser and IdeaScore is encrypted with TLS.

  • Encrypted backups

    Backups are encrypted at rest and taken daily, with a defined retention window before older backups are purged.

  • Audit log

    Administrative actions — approvals, rejections, score changes, user and role changes — are recorded in an audit log.

  • Exportability

    An organisation can export its programme data (submissions, scores, reports) rather than being locked in.

Application security

How the application itself is hardened

  • Input validation

    Form submissions and file uploads are validated server-side, not only in the browser.

  • Rate limits

    API and authentication endpoints are rate-limited to reduce abuse and automated attacks.

  • Dependency updates

    Software dependencies are kept current to reduce exposure to known vulnerabilities.

  • Staging with sanitised data

    Changes are tested on a staging environment using sanitised, non-production data before reaching customers.

Hosting choices

Your cloud or ours

Our cloud

Runs on infrastructure we manage, hosted in India by default. The fastest way to start.

Your own server

IdeaScore runs on an institution's own Apache/VM or Docker deployment, which keeps every byte of programme data on infrastructure the institution already controls — the way to satisfy a strict data-residency requirement.

Responsible disclosure

Found an issue? Tell us

Report a security issue to security@ideascore.online. We acknowledge reports within 3 working days. There is no bounty programme yet.

We do not currently hold SOC 2 or ISO 27001 certification. We will say so here when we do.

Questions your IT team wants answered?

A 30-minute walkthrough with a founder, using your programme's form and criteria.