Security Policy
Scrubz applies layered security controls to protect user accounts, exam data, and subscription operations.
Access Security
- Role-based access controls are used for administrative and student operations.
- Authentication and session protections are enforced across sensitive workflows.
Application and Infrastructure Security
- Input validation and server-side checks are applied to critical actions.
- Operational logging is maintained for payment and access events.
- Security updates and maintenance are applied to reduce known risks.
Payment Security
- Payment processing is delegated to secure gateway providers.
- Raw card credentials are not stored by Scrubz.
Incident Response
- Security events are reviewed and investigated promptly.
- Where required, affected users are notified and corrective steps are taken.
User Security Responsibilities
- Use strong passwords and avoid sharing account credentials.
- Report suspicious activity immediately through support channels.