Never Left Behind

No child is ever left behind

Security and trust

Children's data, protected by design

Safety is the whole point of Never Left Behind — and that extends to how we store, encrypt, and govern every record.

256-bit encryption

TLS 1.3 in transit, AES-256 at rest.

PDPA compliant

Malaysia PDPA 2010, consent-based.

ISO 27001 infra

Google Cloud, Singapore region.

COPPA-ready

Built for under-13 data norms.

How we protect data

Defence in depth

Role-based access

Owner / Admin / Teacher / Staff / Guardian — each sees only what they need. Teachers see their classes; guardians see only their own children. Every access is logged.

Data residency and backups

Hosted in Singapore (asia-southeast1) on ISO 27001-certified infrastructure, with automated encrypted backups and point-in-time recovery.

Audit logs

Every login and sensitive action is recorded (Pro plan). Know who viewed or changed a record, and when.

Your data, always yours

Export everything as CSV, PDF, or a full ZIP at any time. After cancellation, data is retained 90 days then permanently deleted.

Authorised pickup

Photo-verified pickup lists ensure only approved adults can collect a child — critical for custody arrangements.

PCI-compliant payments

All payments run through Stripe's PCI-DSS Level 1 rails. We never see or store full card numbers.

Responsible disclosure

Found a vulnerability?

We take security reports seriously and respond fast. Email security@nlb.thebigdays.com — we'll acknowledge within 24 hours.

Safety you can build on

Start free — every plan includes encryption, role-based access, and audit-ready exports.

Start free