Least privilege, by default
A new role starts with nothing and is granted what it needs. Nobody sees a record they should not because a permission was left switched on from last year.
Security & data protection
Everything below describes how our products are built and operated, and applies to both of them. If you need it in a form your governors, your DPO or your insurer can sign off, ask and we will send the full documentation.
A new role starts with nothing and is granted what it needs. Nobody sees a record they should not because a permission was left switched on from last year.
Every read and write against sensitive data is attributable. If you are ever asked who saw a record and when, the answer exists.
Your data is yours, in a documented schema, exportable in full, at any time, at no charge. That is a design constraint, not a support policy.
Controls
OAuth 2.0 and OpenID Connect, so our products sign in against an identity provider you already run. Multi-factor and conditional access stay where you manage them.
Permissions are enforced server-side on every request. Hiding a button is a courtesy to the user; the API is where the decision is actually made.
Access to sensitive records is logged with the acting user, the record and the time — and kept long enough to be worth having.
Attachments are held outside the database in controlled storage, served through the same permission checks as the record they belong to.
Hosted deployments run in the United Kingdom. Self-hosted deployments run wherever you decide, including entirely on your own infrastructure.
Changes are peer-reviewed and covered by an automated test suite. Anything touching personal data, permissions or payments gets a second, security-specific review.
Sensitive records
A safeguarding note, a medical need, a consent form, a photo ID held because the law requires it — these are not simply more fields on a form. Our products treat them as a separate access boundary: visible to the people who are supposed to see them, invisible to everyone else, and logged either way.
Data protection
You are. A school is the controller for its pupil and staff data; a salon or clinic is the controller for its client records. Block acts as a processor, working on your documented instructions under a data processing agreement.
In the UK for hosted deployments. If you self-host, it never leaves your infrastructure at all — we have no standing access to a self-hosted instance.
A record can be exported in full, including the audit history attached to it, so an SAR is a task you can complete yourself rather than a support ticket to us.
You take a complete export in a documented format, and we delete what we hold to an agreed schedule. There is no exit fee and no proprietary lock on your own records.
Schools have a further set of questions — safeguarding as an access boundary, SEND and medical records, what follows a pupil on transfer. Those are answered in detail on myportaledu.com.
We would far rather hear about a vulnerability from you than from a customer. Report it to hello@blocksoftware.uk and it goes straight to Rowan Richards, who owns security here. We will acknowledge it, keep you updated, and credit you if you would like us to.
Most organisations have one, and most of them ask the same forty questions. We are happy to complete yours, or to talk it through with your IT partner directly.