An extra check at sign-in.
Multi-factor authentication adds a second verification step to help protect accounts.
Secure sign-in, role-based permissions, private evidence storage and active web protection. Built into the way your team works.
Verified identity and provider membership
Role and record permission checks
Authorised reads and time-limited uploads
Secure sign-in, precise permissions, private files and active web protection work together across Journey.
Clerk authenticates each person. Journey verifies their identity before opening their provider workspace.
Tutors, learners, employers and quality teams get access through role and record permissions. Sensitive personal information has additional permission checks.
Evidence is stored privately in Cloudflare R2. Upload links expire, and Journey checks permission before a file is downloaded.
Journey checks the provider workspace when reading and updating records. Your database runs on Neon PostgreSQL in London.
Cloudflare Pro managed firewall rules filter malicious requests at the application edge. Leaked-credential mitigation adds protection against compromised logins.
OWASP Core rules log matching requests for security review. Client-side monitoring adds visibility into scripts running in the browser.
Significant actions record the person, action and time. Your team can follow decisions and changes through the learner's record.
Journey AI retrieves authorised record facts and links answers to evidence. Your team reviews drafts and controls changes to the source record.
Secure identity, a London database and private evidence storage support the same connected record.
| Layer | How Journey protects it |
|---|---|
| Identity | Clerk authentication; Journey controls provider membership, role permissions and record access. |
| Database | Neon PostgreSQL, London. Encrypted database connections with certificate verification. |
| Application | Application functions run in the London region. |
| Evidence files | Private Cloudflare R2 storage in the EU jurisdiction; expiring uploads and authorised downloads. |
| Application edge | Cloudflare Pro managed WAF rules, leaked-credential mitigation, OWASP logging and client-side security monitoring. |
| Data processing | Clerk identity processing is US-based. See the subprocessor register and data-processing terms for service locations and transfer safeguards. |
Clerk Pro supports the following sign-in options. Your organisation’s sign-in policy and enabled settings are agreed during setup.
These are configurable Clerk Pro capabilities. Contact Journey to agree which controls are enabled for your provider.
Access, retention and recovery are part of running your provider’s workspace.
Active membership, role and record permissions determine what each person can open. Changes to a person’s responsibilities can be reflected in their access.
Retention periods, export arrangements, deletion responsibilities and recovery commitments are agreed in your service terms. Contact the team for the recovery and continuity information needed for your procurement.
Report a suspected security issue through our contact page. We will coordinate investigation and customer notification under the applicable service and data-processing terms.
Find the policies, processing information and technology references behind Journey.
Security information updated 11 September 2026.
Bring your learners’ journey, your team’s questions and your next ambition.