Security
Last updated: August 1, 2026
1. Scope of This Page
This page describes how Teloframe is secured today. It is a factual description of measures currently in place, written for customers carrying out due diligence. It is not a warranty, and it deliberately does not claim certifications or audits we have not completed.
For how data is used and shared, see the Privacy Policy. Organizational customers should also read the Data Processing Addendum and the Subprocessors list.
2. Measures in Place
- Encryption in transit - The application and its APIs are served over HTTPS with TLS. Traffic to our hosting, database, and storage providers travels over encrypted connections.
- Authentication - Sessions are managed by a maintained authentication library rather than hand-rolled code. Passwords are stored as hashes, never in readable form. Two-factor authentication is available and optional. Google sign-in is supported for anyone who prefers federated identity.
- Authorization - Club workspaces use defined roles, currently owner, admin, coach, and staff. Player and parent portal access is resolved through a dedicated read layer that scopes every query to the linked player, so a portal account cannot reach club-wide records.
- Input validation - API routes validate their input against explicit schemas before acting on it, and authorization is checked server-side rather than relying on what the interface offers.
- Browser hardening headers - Responses carry X-Content-Type-Options, X-Frame-Options set to DENY, a strict Referrer-Policy, and a Permissions-Policy that disables camera, microphone, and geolocation. A Content-Security-Policy is currently deployed in report-only mode while we remove violations ahead of enforcing it.
- File storage - Player photos, development-plan evidence, and generated data exports are held in private storage and served through controlled, time-limited retrieval. Presentation and gallery media such as match photos, crests, and branding images are stored at unguessable public URLs so they can render in shared pages and exports.
- Managed infrastructure - Hosting, database, and file storage run on managed cloud providers rather than servers we patch ourselves. Secrets are held as environment configuration and are not committed to the codebase.
- Monitoring - Application errors, performance regressions, and failures are reported to an operational monitoring service so problems surface quickly. Significant actions inside a club workspace are recorded for accountability and investigation.
- Abuse and cost controls - AI features carry per-account rate limits, quotas, and cost caps. Uploads are constrained by type and size, and background jobs and billing webhooks are authenticated with shared secrets and signature verification.
3. What We Do Not Claim
We would rather be useful than impressive, so to be explicit: NEXTON INTERACTIVE LIMITED does not currently hold ISO 27001, SOC 2, or an equivalent certification, has not commissioned an independent penetration test, and does not offer a contractual uptime guarantee. We do not operate a paid bug-bounty programme. No online service can guarantee absolute security.
If your procurement process requires any of these, contact us and tell us what you need. We would rather hear it early than discover it at contract stage.
4. Reporting a Vulnerability
If you believe you have found a security vulnerability, email contact@teloframe.com with the subject line starting "Security". Include what you found, the steps to reproduce it, the impact you believe it has, and how we can reach you.
We aim to acknowledge reports within five working days and to keep you updated while we work on a fix. Please give us a reasonable opportunity to resolve the issue before disclosing it publicly. We will not pursue legal action against anyone who reports in good faith, stays within the scope below, and does not access, modify, or retain other people's data.
We do not pay bounties. We are glad to credit you on this page if you would like that.
5. In Scope
- Authentication, session handling, and two-factor flows.
- Authorization, including any way to read or change data belonging to another user, club, or player.
- Player and parent portal scoping.
- Share links, public match pages, calendar feeds, and file storage URLs.
- Billing, seat, credit, and quota logic that could be manipulated.
- Injection, cross-site scripting, cross-site request forgery, and server-side request forgery in the application and its APIs.
Test only against accounts and data you own. If you encounter someone else's personal data, stop, do not save it, and tell us what you saw.
6. Out of Scope
- Denial-of-service, volumetric, or stress testing of any kind.
- Findings that only affect an out-of-date or unsupported browser.
- Reports produced solely by an automated scanner with no demonstrated impact.
- Social engineering, phishing, or physical attempts against us, our staff, or our providers.
- Missing hardening headers or best-practice suggestions with no exploitable consequence.
- Vulnerabilities in third-party services, which should be reported to that provider.
7. Incidents
If we become aware of a personal-data breach affecting data we control, we assess it and give notice where applicable law requires. Where we act as a processor for an organizational customer, we notify that customer without undue delay so it can meet its own obligations, as set out in the Data Processing Addendum.
8. Your Side of the Line
Most incidents in tools like this one start with an account, not a server. Turn on two-factor authentication, use a unique password, remove staff access promptly when someone leaves, treat share links and calendar links as public once sent, and keep children's and health records limited to the people who need them.
9. Contact
NEXTON INTERACTIVE LIMITED, contact@teloframe.com.
P.O BOX 632, 00618 - RUARAKA, NAIROBI, KENYA