Skip to content
Security and your data

Children’s records, in writing.

Your club holds children’s records and parents’ contact details. That makes this your committee’s legal responsibility, so here is exactly what we do with it.

Rule 1

Where your data lives

Production systems run in the India region — Oracle Cloud, Hyderabad — on infrastructure we operate. Data residency is a configuration we can state precisely rather than a claim we imply, and we will put it in a contract.

Rule 2

One tenant can never read another

Isolation is enforced at the database with Postgres row-level security, not by application code alone. That distinction matters: an application bug cannot widen the boundary, because the boundary is not in the application.

Rule 3

Access is role-based, down to the record

Roles run from platform owner through site administrator to end user, and permissions are checked on the server on every request rather than hidden in the interface. Sign-in is passwordless — a provider account or a one-time link — so there are no shared passwords to rotate or leak.

Rule 4

We do not train on your data

Your documents and records are processed to produce your output and for no other purpose. Nothing you give us is used to train a model, ours or anyone else’s, and nothing is pooled across clients. This goes in the contract, not just on this page.

Rule 5

Change safety

The platform that runs in production carries roughly 1,290 automated tests, run on every push. That number is not a security certificate, but it is the honest measure of whether a change can quietly break something that was working.

Rule 6

Built for Indian data protection law

Consent is versioned, so we can show what a person agreed to and when. Personal identifiers are kept separate from the records that get searched. Access, correction and erasure requests are handled as a process with an owner, and erasure reaches every store a record touched, including derived indexes.

Rule 7

Getting your data out

Export is in open formats — CSV, XLSX, PDF and the original files you gave us — available on request and on exit, not as a paid migration. If you leave, you leave with everything, and we would rather agree that up front than negotiate it later.

Send us your security questionnaire

We will complete it. If your procurement process has a standard form, a supplier assurance pack or a set of clauses you need answered, send it over and we will fill it in properly rather than returning a brochure. If the honest answer to a question is "we do not do that yet", that is what you will get.

Send it over
Where we are not yet

No certifications, and we say so.

We hold no security certifications today. For a club platform that is rarely the deciding question, but we would rather tell you than let you assume. If your club’s insurer or governing body requires one, tell us which and we will give you an honest answer about the timeline.

The full picture, including how this is handled across everything Snilld operates, is on the studio’s trust page.

This page describes what is in place today. It is reviewed quarterly, and anything we cannot evidence does not appear on it. Last reviewed 2026-09-27.