studiotasker.
TRUST / TECHNICAL & ORGANISATIONAL MEASURES

Security

Version 2026-10-06.2

Security model

StudioTasker uses layered controls designed for a multi-tenant studio-management SaaS. Security measures are reviewed as the service evolves and are intended to support confidentiality, integrity, availability and tenant separation.

Access and authentication

  • Role-based studio access for owner, manager, instructor and receptionist roles.
  • Server-side membership checks before tenant-scoped operations.
  • HTTP-only session cookies with secure transport requirements in production.
  • Email verification and controlled password-reset challenges.
  • One-way password hashing; plaintext passwords are not stored.

Tenant and database isolation

  • Studio records carry a tenant/studio identifier.
  • PostgreSQL Row Level Security is forced for tenant-scoped tables covered by the application design.
  • The runtime database role is tested to ensure it is not a superuser and cannot bypass RLS.
  • Cross-tenant reads and writes are covered by automated integration tests.

Transport and infrastructure

  • Paid studio registration requires an HTTPS application origin.
  • Application secrets and provider credentials are environment configuration, not committed to the repository.
  • Database connections can require certificate-validated TLS where the production provider supports it.
  • Payment-card data for the StudioTasker subscription is handled by the external billing provider rather than stored in StudioTasker’s application database.

Backups and recovery

  • Paid registration is fail-closed unless backup configuration is present.
  • Backup tooling uses encrypted backup artefacts and verification/restore workflows.
  • Customers should still maintain exports of records they independently need for statutory or business-retention purposes.

Application controls

  • Same-origin checks protect sensitive write requests.
  • Input validation and constrained enums/ranges are applied to core settings and operations.
  • Audit-oriented records exist for selected export, credit-correction, attendance and legal-acceptance events.
  • Automated build/regression tests cover authentication, tenant isolation, mobile/accessibility guards, billing gates, backups and live HTTP behaviour.

Customer responsibilities

Security is shared. Customers should use unique passwords, protect mailbox access, assign the least privilege needed, remove former staff promptly and avoid entering sensitive data the service is not designed to store.

Reporting a concern

If you believe you have found a security issue, use the legal/security contact shown below and provide enough information to reproduce the issue without accessing data that does not belong to you.