Security and data protection
Last updated: June 21, 2026
DrivingOps handles sensitive information about schools, learners, and instructors. We use a risk-based, defence-in-depth approach. This page distinguishes design and environment controls from formal assurance: DrivingOps does not currently claim SOC 2 or ISO 27001 certification.
Architecture and hosting
- Core workloads are designed for Microsoft Azure in Canadian regions.
- Environments and schools are logically isolated; data requests are scoped to the tenant and user's permissions.
- Infrastructure is defined as code for repeatable, reviewable deployment.
- The Cloudflare-hosted marketing site is separated from the operational application.
Encryption and secrets
- Traffic is intended to be encrypted using TLS.
- Managed Azure services provide encryption at rest for databases, storage, and backups.
- Service secrets are stored in Azure Key Vault and injected at runtime rather than committed to source.
- Full payment-card numbers are handled by the payment provider when payments are enabled.
Identity and access
- Microsoft Entra External ID is the planned production identity architecture.
- Roles and permissions limit actions by school, branch, and function.
- Azure services use managed identities where practical.
- Sensitive administrative actions are designed to be logged and reviewable.
- Multi-factor authentication, account lifecycle management, and privileged-access controls are production launch requirements.
Secure development
Changes are managed in source control and subject to automated checks proportionate to risk. Before commercial production, the plan requires dependency and image scanning, configuration checks, tenant-isolation tests, restore exercises, and an independent security assessment.
Logging, monitoring, and audit
The architecture includes Azure Application Insights and Log Analytics for diagnostics and telemetry. Important application events are designed to correlate with a request identifier and, where appropriate, the actor and tenant. Logs should not unnecessarily contain documents, secrets, or payment-card numbers.
Backups and resilience
The development environment currently uses managed PostgreSQL backups with seven-day retention. Production requirements call for longer retention, geo-redundant backups where available, storage soft-delete and versioning, alerting, a documented recovery objective, and periodic restore exercises. These targets are not an SLA unless included in a signed agreement and verified in production.
Incident response
We plan and maintain procedures to detect, contain, investigate, remediate, and document incidents. Notifications to customers, individuals, and regulators are made under applicable law and contract. Customers must also maintain a response plan for information under their control.
Customer responsibilities
- Grant the least permission necessary and promptly remove unneeded access.
- Protect staff devices, accounts, and authentication methods.
- Avoid entering sensitive information in fields not designed for it.
- Review integrations, recipients, retention rules, and exports.
- Promptly report a compromised account or suspicious activity.
Sub-processors and transfers
Providers and possible locations are described in our sub-processor list. Optional payments, WhatsApp, geocoding, or AI features may introduce additional providers and processing locations.
Responsible disclosure
If you believe you found a vulnerability, email hello@drivingops.ca with a description, reproduction steps, and potential impact. Do not access another person's data, disrupt service, use social engineering, or publicly disclose the issue before we have had a reasonable opportunity to investigate. We will acknowledge the report and communicate based on severity.
These are pre-launch documents provided for transparency and legal review. A signed agreement or order form may contain additional terms and will control if there is a conflict. Questions? Contact us.