Trust & security

Trust information for regulated learner data

Secure sign-in, role-based permissions, private evidence storage and active web protection. Built into the way your team works.

Access checked at every layer.

Identity · Clerk

Verified identity and provider membership

Records · Neon PostgreSQL

Role and record permission checks

Evidence · private Cloudflare R2

Authorised reads and time-limited uploads

Secure sign-in, precise permissions, private files and active web protection work together across Journey.

Secure sign-in with Clerk

Clerk authenticates each person. Journey verifies their identity before opening their provider workspace.

  • Verified sign-in
  • Server-checked identity
  • Active provider membership

The right access for every role

Tutors, learners, employers and quality teams get access through role and record permissions. Sensitive personal information has additional permission checks.

  • Role-based permissions
  • Record-level access
  • Sensitive-data controls

Private files. Controlled sharing.

Evidence is stored privately in Cloudflare R2. Upload links expire, and Journey checks permission before a file is downloaded.

  • Private storage
  • Expiring upload links
  • Authorised downloads

Your provider's records stay separate

Journey checks the provider workspace when reading and updating records. Your database runs on Neon PostgreSQL in London.

  • Provider-scoped records
  • Read and write checks
  • London database

Active web-application protection

Cloudflare Pro managed firewall rules filter malicious requests at the application edge. Leaked-credential mitigation adds protection against compromised logins.

  • Cloudflare Pro
  • Managed WAF rules
  • Leaked-credential mitigation

Visibility into suspicious activity

OWASP Core rules log matching requests for security review. Client-side monitoring adds visibility into scripts running in the browser.

  • OWASP request monitoring
  • Security event visibility
  • Client-side monitoring

Know who changed what

Significant actions record the person, action and time. Your team can follow decisions and changes through the learner's record.

  • Named actions
  • Recorded timestamps
  • Traceable changes

AI with the same access boundaries

Journey AI retrieves authorised record facts and links answers to evidence. Your team reviews drafts and controls changes to the source record.

  • Permission-controlled answers
  • Evidence links
  • Human review
OUR SECURITY TECHNOLOGY

The technology behind your protection.

Secure identity, a London database and private evidence storage support the same connected record.

LayerHow Journey protects it
IdentityClerk authentication; Journey controls provider membership, role permissions and record access.
DatabaseNeon PostgreSQL, London. Encrypted database connections with certificate verification.
ApplicationApplication functions run in the London region.
Evidence filesPrivate Cloudflare R2 storage in the EU jurisdiction; expiring uploads and authorised downloads.
Application edgeCloudflare Pro managed WAF rules, leaked-credential mitigation, OWASP logging and client-side security monitoring.
Data processingClerk identity processing is US-based. See the subprocessor register and data-processing terms for service locations and transfer safeguards.
CLERK PRO · SIGN-IN OPTIONS

Identity controls for your organisation.

Clerk Pro supports the following sign-in options. Your organisation’s sign-in policy and enabled settings are agreed during setup.

01 · MFA

An extra check at sign-in.

Multi-factor authentication adds a second verification step to help protect accounts.

02 · ENTERPRISE SIGN-IN

Connect your identity provider.

Clerk Pro includes one enterprise connection. Organisation-specific single sign-on needs configuration and may require an additional plan option.

03 · SESSIONS & LOGS

Control sessions. Follow activity.

Configurable session lifetimes and seven-day Clerk application logs support account administration.

These are configurable Clerk Pro capabilities. Contact Journey to agree which controls are enabled for your provider.

Clerk Pro feature details

DATA & OPERATIONS

Control access throughout the record.

Access, retention and recovery are part of running your provider’s workspace.

PEOPLE & PERMISSIONS

Access follows the person.

Active membership, role and record permissions determine what each person can open. Changes to a person’s responsibilities can be reflected in their access.

RETENTION & RECOVERY

Keep your records manageable.

Retention periods, export arrangements, deletion responsibilities and recovery commitments are agreed in your service terms. Contact the team for the recovery and continuity information needed for your procurement.

INCIDENT RESPONSE

A clear route to the team.

Report a suspected security issue through our contact page. We will coordinate investigation and customer notification under the applicable service and data-processing terms.

See what changes
when it all connects.

Bring your learners’ journey, your team’s questions and your next ambition.