Security is a shared responsibility between Easy School Bus Management, schools, providers, administrators, drivers, families, and infrastructure partners.
Platform Safeguards
- Encrypted HTTPS transport and Firebase-managed authentication.
- Role-, school-, and region-based Realtime Database rules.
- Server-only payment, platform-role, public-store, and public-inquiry operations.
- Input validation, anti-abuse rate limiting, restricted tokens, and App Check support.
- Payment tokenization through supported payment providers; full card details are not stored by EasySchoolBus.
- Security headers, protected administrator functions, and error logging that avoids exposing credentials.
User and School Responsibilities
- Use unique passwords and protect devices and access codes.
- Remove former staff promptly and review route, student, and driver assignments.
- Share public store links intentionally and disable them when no longer needed.
- Do not send passwords or payment-card details through messages or support forms.
Responsible Disclosure
Report a suspected vulnerability through Support and select “Security report.” Include reproducible details without accessing, downloading, changing, or publishing other users’ data. Do not use automated destructive testing against production. We will acknowledge and triage legitimate reports.
Security Incidents
If a confirmed incident affects personal information, we will investigate, contain, remediate, and notify affected organizations, users, or regulators where required.