Security & Data Protection
How we protect your account, your documents, and your data.
1. Overview
SizaPoint is built on established cloud infrastructure with security controls appropriate for handling academic and personal data. We follow the principle of least privilege throughout our systems: people and services only get the access they need to do their job.
2. Authentication and Access Control
- Account sign-in uses secure, industry-standard authentication. Passwords are never stored in plain text — they are salted and hashed using modern cryptographic standards.
- Access to your documents and account data is restricted to your account and, where applicable, your institution's authorised administrators.
- Internal access to production systems is limited to authorised personnel and logged.
3. Data Isolation
Each account and institutional tenant is logically separated, with role-based permissions controlling what data a given user or institution can see and act on.
4. Encryption
- Data is encrypted in transit using TLS between your browser and our servers.
- Data is encrypted at rest in our cloud storage and database infrastructure.
5. Monitoring and Incident Response
We monitor our systems for unusual activity and maintain an incident response process. In the event of a security incident affecting your personal data, we will notify affected users and relevant authorities as required by applicable law.
6. Vulnerability Reporting
If you believe you've found a security vulnerability in SizaPoint, please report it responsibly to security@sizapoint.com (or the Contact page under "Technical support") rather than testing it against other users' accounts. We will acknowledge reports and work to resolve confirmed issues promptly.
7. Sub-processors
We use a small number of vetted service providers (for hosting, email delivery, and payments) under contracts that require them to protect your data to a standard consistent with this page and our Privacy Policy.
Have a question about this document? Contact us.
