Security
Security
Last Updated: April 20, 2026
Our Commitment to Security
At CubbyPro, protecting the data of children, families, and childcare centres is our highest priority. We employ enterprise-grade security measures across every layer of our platform to ensure your information remains safe, private, and accessible only to authorized users.
Infrastructure and Hosting
- Canadian Hosting. Customer Data — including child records, attendance, photos, messages, and financial data — is stored on infrastructure located in Canada.
- Certified Cloud Provider. Our primary cloud provider maintains SOC 1, SOC 2 Type II, ISO 27001, and ISO 27017 certifications and operates in a Canadian data centre region. These certifications apply to the underlying infrastructure; CubbyPro's own SOC 2 certification is in progress (see Compliance section below).
- Limited US-Based Services. Authentication credentials, optional AI inference on non-personal parameters, and payment processing (when enabled) are handled by service providers located in the United States. This is disclosed in detail in our Privacy Policy §8.
- Tenant Isolation. Each childcare centre operates in a logically isolated tenant. Cross-tenant data access is prevented at the database query level — tenant-scoped queries are enforced on every API endpoint.
- Database. Managed PostgreSQL with automated backups, point-in-time recovery, and private-IP networking.
- Secrets Management. All sensitive configuration values (API keys, database credentials, service account keys) are stored in a managed secret store and injected at runtime — never hardcoded or committed to source control.
Encryption
- In Transit. All data transmitted between your device and CubbyPro servers is encrypted using TLS 1.2 or higher. HTTPS is enforced on all endpoints.
- At Rest. All data stored in our databases, object storage, and backups is encrypted at rest using industry-standard encryption (AES-256) managed by our cloud provider.
- Application-Level Encryption. Highly sensitive fields such as OHIP numbers are additionally encrypted at the application level using AES-256-GCM before being written to the database.
Authentication and Access Control
- Authentication. Supports Google Sign-In, Apple Sign-In, and email/password. Multi-factor authentication (TOTP and SMS) is in progressive rollout.
- Kiosk Security. Classroom kiosk devices use signed device tokens with QR-code-based registration and PIN-based staff clock-in.
- Role-Based Access Control. The platform enforces strict role-based permissions. Parents see only their own children. Teachers see only their assigned classrooms. Directors have centre-wide visibility.
- Rate Limiting. API endpoints are protected by rate limiting to deter brute-force attacks and abuse.
- Audit Logging. Administrative and sensitive actions are logged with actor, timestamp, and context for review.
Application Security
- Authorization Checks. All API endpoints validate that the requesting user has authorization to access the requested resource (protection against Insecure Direct Object Reference vulnerabilities).
- Input Validation. User inputs are validated and sanitized on both the client and server side.
- Dependency Scanning. We scan application dependencies for known vulnerabilities and apply security patches on a regular cadence.
- Secure Development. Development practices include code review, automated testing, and deployment through CI/CD pipelines. Direct production access is restricted.
- Security Reviews. We conduct internal security reviews of material changes. Independent third-party penetration testing is part of our SOC 2 readiness roadmap.
AI Security
- AI features are powered by trusted third-party AI providers.
- No personally identifiable information — including child names, parent details, OHIP numbers, or photos — is sent to AI providers.
- AI inputs are limited to non-identifying parameters such as class name, age group, and selected theme.
- Data submitted to AI features is not used to train general-purpose AI models.
- All AI-generated output is presented for human review before being saved, shared, or acted on.
Compliance
- PIPEDA. CubbyPro operates in compliance with the Personal Information Protection and Electronic Documents Act, Canada's federal privacy law.
- PHIPA. Where applicable, we align our handling of health-related information with Ontario's Personal Health Information Protection Act.
- CCEYA. Our platform supports Ontario childcare centres' compliance with the Child Care and Early Years Act, 2014, including ratio tracking, licensing documentation, and inspection preparedness. Compliance with CCEYA requirements remains the centre's responsibility.
- CWELCC. CubbyPro generates reports aligned with the Canada-Wide Early Learning and Child Care program requirements, including FTE calculations, fee cap compliance, and workforce reporting.
- SOC 2 Ready. CubbyPro's controls are designed against the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality). We are "SOC 2 Ready" — meaning our controls are in place and ready for formal audit — but we are not currently SOC 2 certified. Customers who require a current SOC 2 attestation report may contact us for the status of our readiness program.
Incident Response
In the event of a security incident:
- Our team is alerted through automated monitoring and alerting on critical signals.
- We follow an internal incident response process that covers containment, investigation, remediation, and post-incident review. This process is maintained internally and reviewed periodically.
- Affected customers and individuals will be notified in accordance with applicable Canadian privacy laws (including PIPEDA breach notification requirements) and any applicable regulatory timelines.
- Audit logs of administrative actions and sensitive data access are retained to support forensic investigation.
Responsible Disclosure
If you discover a security vulnerability in CubbyPro, we encourage responsible disclosure. Please report security issues to security@cubbypro.com. We will acknowledge receipt within 48 hours and work with you to understand and address the issue promptly.
Contact
For security-related questions or concerns, contact us at:
CubbyPro Security Team
Email: security@cubbypro.com
Office 184, 145 1/2 Church Street, Unit 5
Toronto, Ontario M5B 1Y4, Canada