Your studio holds sensitive information about children and families. Protecting it isn’t an afterthought — it’s built into the foundations of StudioSync.
Every studio's data is isolated at the database level using PostgreSQL Row-Level Security. One studio can never see another's data — the boundary is enforced by the database itself, not just application code.
Passwords are hashed with scrypt, a memory-hard algorithm designed to resist brute-force attacks. Plain-text passwords are never stored, and we can never see yours.
Add a second layer of protection with TOTP-based two-factor authentication from any authenticator app, backed by one-time recovery codes so you never lose access to your account.
Studio-scoped roles mean each person sees only what their job needs. Platform operators use a separate, read-only path for support — with no ability to reach into your day-to-day data.
Fees are collected through PayFast, a trusted South African payment provider. Card details are entered on PayFast's secure checkout and never touch our servers.
Your data is backed up regularly and hosted in South Africa (af-south-1), keeping it close to your studio and your families for both performance and peace of mind.
We welcome reports from security researchers. If you believe you’ve found a vulnerability, please get in touch with the details so we can investigate and resolve it. We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, and that you avoid accessing or modifying data that isn’t yours while testing.
Have a question about how we protect your data? We’re happy to talk it through.