Legal
Security
Last updated: 1 June 2026
Our security philosophy
Security at High Scholar is not a feature — it is a foundational design requirement. We apply a defence-in-depth approach, layering technical controls, organisational procedures, and continuous monitoring to protect the data of learners, educators, and families.
Infrastructure security
- All production infrastructure is hosted in ISO 27001-certified South African data centres.
- Network segmentation separates production, staging, and internal systems.
- Web Application Firewall (WAF) rules are applied at the edge to filter malicious traffic.
- DDoS mitigation is active at both the network and application layers.
- Infrastructure access is gated by hardware MFA and restricted to a named list of senior engineers.
Data encryption
- All data at rest is encrypted using AES-256.
- All data in transit is protected by TLS 1.3 with HSTS enforced on all domains.
- Database backups are encrypted with a separate key hierarchy and stored in a geographically separate facility.
- Encryption keys are managed through a dedicated key management service with automatic annual rotation.
Application security
- All code undergoes peer review and automated static analysis before deployment.
- Dependencies are scanned for known vulnerabilities on every build.
- SQL injection, XSS, CSRF, and SSRF protections are applied at the framework and middleware level.
- Rate limiting and brute-force protections are applied to all authentication endpoints.
- Session tokens are rotated on privilege escalation and expire after 30 days of inactivity.
Access control
We operate a strict least-privilege access model. Employees access only the data necessary for their role. All internal access to production data is logged, audited quarterly, and reviewed on employee role change or departure. Privileged access sessions are recorded and stored for 12 months.
Vulnerability management
- Annual penetration tests conducted by an accredited third-party security firm.
- Quarterly internal vulnerability scans.
- A responsible disclosure programme is maintained at security@highscholar.co.za.
- Critical vulnerabilities are patched within 24 hours; high-severity within 7 days.
Incident response
We maintain a documented incident response plan reviewed annually. In the event of a security incident affecting personal data: affected users are notified within 72 hours of confirmation; the Information Regulator is notified as required by POPIA; a post-incident review is completed within 14 days; and remediation actions are tracked to closure.
Business continuity
Production databases are backed up continuously with point-in-time recovery available for 30 days. A full disaster recovery drill is conducted twice per year with a target Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 15 minutes.
Responsible disclosure
If you believe you have discovered a security vulnerability in the High Scholar platform, please report it to security@highscholar.co.za. We ask that you provide sufficient detail to reproduce the issue and give us a reasonable timeframe to respond before any public disclosure. We do not pursue legal action against researchers who disclose in good faith.
Questions about this document? legal@highscholar.co.za