Security
What a school's IT reviewer gets from Harbor, and how to ask for it. The Security Overview and the data processing agreement are sent on request, so a person can answer the questions that follow.
Last updated 20 September 2026
What Harbor sends your IT reviewer
- The Security Overview. Architecture and data residency (database, authentication and file storage on Supabase, running on Amazon Web Services in the Sydney region; the application on Vercel), how access is controlled, audit logging, the secure links families use instead of passwords, operational security, the privacy and compliance posture, incident response, and a plain list of what Harbor has not done yet, including that Harbor does not hold SOC 2 or ISO 27001 certification.
- The data processing agreement. The school is the agency holding the personal information and Harbor processes it on the school's instructions, with the service providers named.
- A person to answer the questionnaire. Most schools have one; send it and the answers come back from someone who can be asked a follow-up.
How to ask
Email hello@harbor.co.nz with your school, your role and what your review needs to cover. Both documents come back by reply, from a person.
What is public already
- Database and documents are held in AWS Sydney under the NZ Privacy Act 2020. If New Zealand-only residency is a hard requirement for your school, raise it before contracting.
- Every school's data is isolated by policy at the database, and every server route checks who is asking and which organisation they belong to before it touches data.
- Every action is written to an audit log with who did it and when; the log cannot be edited or deleted.
- Families and hosts work from expiring, hashed links, never a password.
- Uploaded documents and photos are private and served only through short-lived signed links.
- Uptime is published at the status page.
- The Privacy Policy sets out the service providers and the breach process.
Reporting a vulnerability
If you find a security problem in Harbor, Harbor wants to hear about it. The responsible disclosure policy says how to report it and what Harbor commits to in return. The machine-readable version is at /.well-known/security.txt.