Security
Security practices, stated plainly
What we do today, in plain terms. No certifications are claimed.
Access control
Who can see and change what
Five roles
Organisation isolation
Session lockout
Re-authentication for sensitive edits
Data protection
How data is stored and moved
TLS in transit
Encrypted backups
Audit log
Exportability
Application security
How the application itself is hardened
Input validation
Rate limits
Dependency updates
Staging with sanitised data
Hosting choices
Your cloud or ours
Our cloud
Your own server
Responsible disclosure
Found an issue? Tell us
Report a security issue to security@ideascore.online. We acknowledge reports within 3 working days. There is no bounty programme yet.
Questions your IT team wants answered?
A 30-minute walkthrough with a founder, using your programme's form and criteria.