Security and incident response
Controls visible in the application, operational evidence still needed and how to report a concern.
Version 1.1 · Updated 7 September 2026. Published by Glu IO Pty. Ltd., the owner and operator accountable for Helper Shifts. Committee-specific agreements take effect when signed.
Controls evidenced in code
- Organiser passwords are bcrypt-hashed. Account verification, invitation, reset and helper-access tokens use stored hashes rather than raw tokens.
- Signed HTTP-only sessions distinguish organiser and helper access. Group membership and ownership checks restrict administration.
- Queries include group scoping. Database row-level security and composite constraints are defined in finalisation migrations; production application of those migrations and the database role’s restrictions must be verified.
- Parameterized SQL and input validation reduce injection risk. Mutation endpoints use JSON-content-type checks, alongside session controls.
- HTTPS redirects and TLS configuration are defined in the infrastructure. Browser headers disable framing and unnecessary camera, microphone and geolocation permissions.
- Dynamic responses use cache-control headers to prevent caching. Helper access-email limits share database-backed state with keyed email/IP identifiers.
These findings are a code/configuration review, not a penetration test, deployment verification or statement that every endpoint is protected against every attack. Search-engine noindex directives help reduce discovery of group pages but are not access controls; published events remain public.
Evidence and controls still required
Committees assessing the service can request evidence of privileged-account MFA, least-privilege production access and reviews, database encryption and key management, deployment and dependency scanning, patch response times, independent penetration testing, monitoring and alert response, tested backup restoration, and staff confidentiality/training.
Organiser MFA and enterprise identity federation are not evidenced in the reviewed app. No verified recovery time, recovery point, uptime SLA, incident-response exercise, complete audit trail or independent security report is supplied by this pack. These gaps must be resolved or accepted through the committee’s authorised process.
The review also identified dependency security advisories and a database TLS certificate-validation setting requiring remediation and deployment testing. This pack must not be treated as confirmation that the service has passed a security review.
Committee and organiser responsibilities
Use named accounts and strong unique passwords, review owners and co-admins at staff turnover, protect email accounts with MFA, avoid shared-device storage, restrict CSV distribution and delete copies under the committee’s records policy. Keep public descriptions free of personal or sensitive information. Test access using the roles the committee will actually use.
For lost or compromised email access, escalate promptly: a helper’s email account can be used to obtain access to that helper’s bookings. Signing out on shared devices reduces local session exposure.
Reporting a security concern
Service operator: Glu IO Pty. Ltd. — owner and operator of Helper Shifts, ultimately accountable for the service.
Privacy, security and committee enquiries: A monitored service contact is awaiting confirmation. Existing users can contact their group organiser through their usual committee communication channel.
Include your group address, the nature of your request and a safe way to reply. Do not send passwords, sign-in links, student records or identity documents in an initial message.
Provide the affected URL without secret query tokens, approximate time and timezone, a description of the behaviour and minimal redacted evidence. Stop when you encounter another person’s information. Do not download other groups’ data, test destructively, disrupt availability or publish personal information. This page is not permission to conduct intrusive security testing.
A monitored incident contact and escalation owner must be confirmed before a committee contract is executed. No 24/7 monitoring or response-time guarantee is currently claimed. Report service incidents directly to Glu IO Pty. Ltd. and notify the affected committee organiser; follow any other incident-reporting duties that apply to your organisation.
Incident response procedure
The response procedure is: record and triage the report; contain exposure while preserving evidence; determine affected groups, records and likely harm; notify affected committee contacts promptly; assess statutory notification duties with legal advice; communicate updates; restore safely; and document the cause and corrective action.
The DPA requires initial committee notification within 24 hours of awareness, including suspected incidents, subject to an agreed operational schedule. The notification period applies when the DPA is incorporated into the signed committee contract. A federal 30-day assessment period must not be treated as permission to delay urgent action or committee notification. See the OAIC response guidance.
Document history: version 1.1 — clarified independent committee use and contact responsibilities, 7 September 2026; version 1.0 — published documents, Australian data storage and Glu IO Pty. Ltd. operator identity, 7 September 2026; version 0.2 — clarified administrator contact-use restrictions, 7 September 2026; version 0.1 — initial publication, 6 September 2026. Print or save this page as PDF to retain this version. Committee agreements and applicable law take priority over general guidance.