Security
MartialOps takes the security of school and student data seriously. This page describes our security posture and how to report a vulnerability responsibly.
Responsible Disclosure
If you discover a security vulnerability in MartialOps, please report it by email to security@martialops.app. Include a description of the issue, steps to reproduce, and the potential impact. We will acknowledge your report within 3 business days and work with you to resolve confirmed vulnerabilities promptly.
Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.
Infrastructure
- Data in transit: All communication between clients and our servers is encrypted using TLS.
- Data at rest: Databases and backups are encrypted at rest.
- Tenant isolation: Each school's data is logically isolated — a user authenticated to one school cannot access another school's records.
- Access controls: Staff access is role-based; the minimum permissions required for each action are enforced at the API level.
Third-Party Sub-processors
For the current list of sub-processors and third-party services we use to operate MartialOps, please contact us.