Security
Security and data protection.
Data minimisation
- Driver records hold authorisation, the date a licence was checked and when the next check is due. We don't ask for licence numbers or scans.
- Trips record passenger numbers — not pupils' names or details.
- We only keep the DVSA/DVLA vehicle data VORMS actually uses (such as MOT expiry and tax status).
Separation between schools
Every record belongs to one organisation. Access is enforced on the server for every request, not just hidden in the interface, and our automated tests check that one organisation can never read another's data.
Accounts and access
- Passwords are stored using Argon2id hashing; we never store or see your password.
- Optional two-step verification with an authenticator app for every user.
- Roles control what each person can do, and users can be limited to one school.
- Sign-in attempts are rate limited and accounts lock temporarily after repeated failures.
VORMS staff access
Our internal administration system is only reachable from approved networks and requires two-step verification. If our support team needs to see your account to help you, it happens in a clearly marked, read-only support session by default, and it's recorded in your organisation's audit log.
Infrastructure
- All traffic is encrypted with HTTPS.
- Documents and photos are stored privately and are only available to signed-in users with permission.
- Databases are backed up automatically every day to encrypted backups.
Audit trail
Important actions — sign-ins, bookings, checks, defects, permission changes, billing changes — are recorded in an append-only audit log that can't be edited.
Your responsibilities
Your school remains responsible for its own vehicle and driver policies and for decisions about who may drive. VORMS helps you record and follow those policies.
Reporting a security issue
If you think you've found a security problem, please contact us and we'll respond promptly.
