← Verto home

Security in the pilot

Verto uses password hashing, revocable account sessions and server-verified school and campus memberships. Student records and enrollment audit events are scoped by PostgreSQL row-level security. Enrollment and its audit event are saved in one transaction.

Operating requirements

A deployment requires HTTPS, a restricted database account, protected secrets and operator-managed backups. Multi-factor authentication, password recovery and automated retention are not implemented. Monitoring and backup restoration must be configured and verified before live school use.

Report a concern

Use the contact form to request a security follow-up. Do not include passwords, session tokens, student records or exploit details in that form.