Children's data, protected by design
Safety is the whole point of Never Left Behind — and that extends to how we store, encrypt, and govern every record.
256-bit encryption
TLS 1.3 in transit, AES-256 at rest.
PDPA compliant
Malaysia PDPA 2010, consent-based.
ISO 27001 infra
Google Cloud, Singapore region.
COPPA-ready
Built for under-13 data norms.
How we protect data
Defence in depth
Role-based access
Owner / Admin / Teacher / Staff / Guardian — each sees only what they need. Teachers see their classes; guardians see only their own children. Every access is logged.
Data residency and backups
Hosted in Singapore (asia-southeast1) on ISO 27001-certified infrastructure, with automated encrypted backups and point-in-time recovery.
Audit logs
Every login and sensitive action is recorded (Pro plan). Know who viewed or changed a record, and when.
Your data, always yours
Export everything as CSV, PDF, or a full ZIP at any time. After cancellation, data is retained 90 days then permanently deleted.
Authorised pickup
Photo-verified pickup lists ensure only approved adults can collect a child — critical for custody arrangements.
PCI-compliant payments
All payments run through Stripe's PCI-DSS Level 1 rails. We never see or store full card numbers.
Responsible disclosure
Found a vulnerability?
We take security reports seriously and respond fast. Email security@nlb.thebigdays.com — we'll acknowledge within 24 hours.
Safety you can build on
Start free — every plan includes encryption, role-based access, and audit-ready exports.
Start free