Security

How we protect your data

Most of our records are about teenagers, so we treat them that way. Here is what we do today, written plainly, and what we haven't done yet.

Who protects your data

  • Who is accountable. DMV Zone's founders, the owners of the driving school that built RoadVerified, are personally responsible for security. Student details are encrypted before they reach our database host, and the key is kept apart from it.
  • Who can see what. A school sees only its own students. An insurer sees a certificate only when the family sends it or gives them its code. Our team's back end shows schools and insurers, not student records, and every team login needs a code sent by email.
  • How we watch for leaks. Every insurer lookup is logged in a record that can't be edited. We get an alert when an insurer account searches far more than usual. Insurer logins that go unused for 90 days are switched off, and every insurer partner is checked again each year. Each night we re-check the public ledger, so a changed certificate can't go unnoticed.
  • If something goes wrong. We will tell affected schools and insurers without delay, and within 72 hours of confirming a breach. We will notify families and the authorities as state law requires (in New Jersey, the State Police first). Because student details are encrypted and we keep only the last 4 characters of permit numbers, a stolen copy of the database would not reveal them.
  • Contracts. Insurers sign a data access agreement before they get a login. It bans reselling data and requires them to report any breach to us. Our terms, privacy policy and insurer agreement will be reviewed by a New Jersey attorney before launch.

Want the details of how a certificate is protected from fakes? Read how our certificate check works.

Student data

  • Encrypted fields. Student emails, birth dates and addresses are encrypted with AES-256-GCM before they reach the database. The key is kept apart from the database, so a copy of the database alone can't be read.
  • We keep less. Permit and license numbers are stored as the last 4 characters only. Public check pages show the birth month and year, never the full date.
  • No browsing. Nobody outside a school can list its students. Insurers see a certificate only when the family sends it or gives them its code and last name.
  • Deleted on a schedule. Owner ID photos are deleted after review. After 5 years, student details are removed and only the code and its status stay.

Accounts

  • Strong passwords. Passwords are at least 10 characters, checked against lists of leaked passwords, and stored only as a salted scrypt hash.
  • Login codes. School owners, admins and insurers confirm each new device with a 6-digit code sent by email. Insurers enter a code at every login.
  • Locked school identity. A school's name, license number and state lock once it starts issuing. Changes need the state document and a review by our team, and a license can belong to only one account.
  • Limits on guessing. Logins, codes and certificate checks are rate limited.

Certificates

  • Tamper seal. Every certificate carries a security seal computed from its contents with a secret key. Changing a name, date or hour count breaks it.
  • One official PDF. We keep a fingerprint of each certificate's PDF. Anyone can upload a copy on the check page to see whether it was altered.
  • Logs that can't be edited. Every insurer lookup and school action is written to a log that blocks edits and deletions.
  • Public ledger. Every certificate event goes into a public, append-only ledger of hashes. Nobody, including us, can quietly backdate or change a certificate.

The basics

  • HTTPS everywhere, with strict security headers. The site can't be framed by other sites.
  • Uploaded files are checked to be real PDFs or photos and opened in a locked-down viewer.
  • We check our code dependencies for known security problems and patch them.

What we haven't done yet

We have not had an outside security audit, penetration test or SOC 2 report. We plan a penetration test before insurers rely on the portal at scale, and SOC 2 as we grow. Until then we won't claim otherwise.

Found a problem? Tell us through support and we'll fix it fast.