Security Overview
Last updated: 15 July 2026
This page gives prospective and current customers a clear overview of how 25Thirty Ltd protects Bridge Admissions. It must be checked against the actual architecture before publication.
Security principles
We design and operate Bridge Admissions around:
- least-privilege access;
- secure defaults;
- separation of customer data;
- encryption;
- logging and monitoring;
- resilient backups;
- controlled software change;
- prompt incident response;
- data minimisation.
Hosting and data location
Primary hosting provider: [PROVIDER]
Primary region: [UK/EEA REGION]
Backup region: [REGION]
International transfers: [SUMMARY AND LINK]
Encryption
- Data in transit is encrypted using current TLS.
- Production databases and backups are encrypted at rest.
- Secrets and encryption keys are managed using [SERVICE/PROCESS].
- [CONFIRM WHETHER FIELD-LEVEL ENCRYPTION IS USED.]
Identity and access
- Unique user accounts and role-based permissions.
- Multi-factor authentication: [REQUIRED/AVAILABLE/ROADMAP].
- Single sign-on: [MICROSOFT/GOOGLE/OTHER].
- Restricted privileged access with logging.
- Staff access is limited to legitimate support, security and operational needs.
Application security
- Code review and controlled deployment.
- Dependency and vulnerability scanning.
- Security updates and patch management.
- Separation of development, test and production environments.
- Protection against common web-application risks.
- Independent penetration testing: [FREQUENCY/LAST TEST].
- Responsible disclosure contact: [SECURITY EMAIL].
Data protection
- Schools control their own records and user permissions.
- Customer data is not sold or used to advertise to families.
- Data export and deletion processes are available.
- Subprocessors are assessed and contractually bound.
- Sensitive data should be minimised and access restricted.
Monitoring and incidents
We monitor service health, security events and unusual activity. We maintain an incident-response process covering containment, investigation, recovery, customer communication and lessons learned.
Customers are notified of personal data breaches without undue delay in accordance with the Data Processing Agreement.
Resilience
- backup frequency: [DETAIL];
- backup retention: [DETAIL];
- restoration testing: [DETAIL];
- availability target: [DETAIL];
- recovery point objective: [DETAIL];
- recovery time objective: [DETAIL].
Assurance documents
Available under confidentiality where appropriate:
- Data Processing Agreement;
- subprocessor list;
- security questionnaire responses;
- penetration-test executive summary;
- relevant policies and evidence;
- cyber-insurance details [IF APPLICABLE].
Contact [SECURITY EMAIL] for security questions.