Legal
Security
This page is maintained by the operator of Ratio to answer common security questions about the product. It describes controls that are switched on today. It is not a certification, an audit report, or a guarantee that no issue exists.
Last updated 5 August 2026
Signing in
- Sign-in is by one-time magic link sent to your email address. There is no password to guess, reuse or leak.
- Links are single use and expire, and sessions can be signed out from the app.
- Only email addresses you invite can reach your centre's data; there is no open sign-up into an existing account.
Who can read your records
- Every table holding staff, credential, evidence and activity data has row-level security enabled, and policies scope reads and writes to the accounts attached to that centre.
- Evidence files live in private storage. Files are served through short-lived signed links, not public URLs.
- Self-onboarding links are scoped to a single submission and cannot read your roster or anyone else's records.
Data in transit and at rest
All traffic to Ratio is served over HTTPS. Data and uploaded files are held on managed cloud infrastructure that handles storage-level encryption, patching and backups for the platform. We do not claim end-to-end encryption: the application can read your records in order to calculate status and build reports.
Change history
Ratio keeps an activity log of who changed what and when, including credential edits, evidence uploads and recorded register checks. The log is written by the database rather than the browser, so it reflects what actually happened to the record.
Shared responsibility
Some controls are ours and some are yours. We provide the platform controls above. You are responsible for keeping your sign-in inbox secure, inviting only the people who should see staff records, removing access when someone leaves, and verifying credentials on the official register rather than trusting an uploaded image alone.
Data minimisation
Ratio holds no information about children, families or enrolments, and there is no field anywhere in the product to enter it. Staff records are limited to what a compliance check needs: identity, role, credential numbers, dates and evidence.
Reporting a vulnerability
If you believe you have found a security issue, contact the operator of your Ratio account with the details and give us a reasonable window to respond before disclosing it publicly. Please do not test against real centre data or attempt to access records that are not yours. Add your organisation's security contact address here before you publish the site.