CodeInFront Security
Effective date: 18 August 2026
Operated by: CodeInFront (ABN 71 362 605 165) ("we", "us", "CodeInFront")
Contact: support@codeinfront.com.au
For schools completing a technology risk assessment
CodeInFront is not certified, approved, or endorsed by any Australian education department — across states and territories, that determination sits with the individual school, not with us. This page describes our actual technical controls, as built, so that assessment can be made quickly and accurately. See also our Privacy Policy for what personal information is (and isn't) collected.
1. Compliance
We handle personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles. See our Privacy Policy for what we collect, why, and how you can exercise your rights over it.
2. Infrastructure and data locality
- The Platform and its database are hosted with DreamITHost, an Australian hosting provider — your data is stored on servers located in Australia. Data does not leave Australia at any point.
- All traffic to the Platform is encrypted in transit (HTTPS/TLS).
- The database is not reachable from outside our hosting provider's own network, and access to the underlying systems is limited to the Platform operator.
- We don't run any third-party analytics, advertising, or tracking scripts — see our Cookie Policy.
3. Authentication and access control
- Passwords (teacher, admin and student) are never stored in plain or reversible form — only as one-way cryptographic hashes (bcrypt, via PHP's
password_hash()). Nobody, including us, can look up an existing password; resetting is the only recovery path.
- Login attempts are rate-limited: an account locks out for 15 minutes after 5 failed attempts in a row, which blunts automated password-guessing.
- Every form submission is protected against cross-site request forgery (CSRF) with a per-session token, checked using a timing-safe comparison.
- Session cookies are
HttpOnly (invisible to page JavaScript), Secure on HTTPS connections, and scoped SameSite=Lax. Sessions expire when the browser closes — there is no long-lived "remember me" token.
- Multi-factor authentication is not currently offered. Given the Platform holds no personal student information at all (see Privacy Policy §2), and teacher/admin accounts hold only an email, username and school name, we've prioritised other controls first — this is something we're open to discussing as part of a school's assessment.
- Student accounts cannot self-register or change their own username — only a teacher can create, reset, suspend or remove one, from a single class-scoped console.
4. Data minimisation as a control
The Platform is deliberately built to hold as little as possible in the first place — see our Privacy Policy for the complete list of what's collected. A student account is a system-generated username and password with no identifying information attached to it at all. This isn't just a privacy position — it directly shrinks what a security incident could ever expose, since there's no student name, date of birth, email address, or other personal record in the system to begin with.
5. Reporting a security issue
If you believe you've found a security vulnerability in the Platform, please email support@codeinfront.com.au with details rather than testing it against live accounts or data. We commit to:
- acknowledging your report and working with you to understand and fix the issue;
- not pursuing legal action against, or disabling the account of, anyone who reports a vulnerability to us in good faith and doesn't access, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
6. Contact
Questions about this page: support@codeinfront.com.au