Privacy & Security Audit
A plain-language record of the controls verified in CampusVerify as of 30 September 2026.
Scope and status
This is an internal product and code review, not an independent certification, legal opinion, penetration test, or claim of complete security. It covers the current website, authentication, database access rules, survey workflows, payments, and app-email triggers.
Verified controls
Account identity
Every account requires email confirmation. Student accounts additionally require a recognised academic email domain; General/Researcher accounts are email-confirmed but are not academically verified.
Data access
Database access rules separate private account data, survey ownership, responses, administrative tools, and public survey information. Sensitive profile and survey fields are protected from direct user changes.
Roles
Administrative, manager, and faculty permissions are stored separately from user profiles and checked by trusted backend functions.
Survey access
Survey owners control private invitations and progress access. Invitees must register and accept with the same confirmed email address. Super-admin assistance notifies the survey owner.
Payments
Payment confirmation is verified before credits or paid features are granted. CampusVerify does not store full payment-card details.
Transport and credentials
Traffic uses encrypted connections. Password handling is delegated to the authentication provider and passwords are not stored in readable form by CampusVerify.
Data minimisation
Public pages use limited survey information. Lecturer email addresses and sensitive account fields are not available through ordinary public or signed-in data access.
Important limitations
- Email confirmation verifies control of an inbox; it does not prove how a person completes a survey or guarantee that every answer is truthful.
- Academic-domain checks establish eligibility for a student account, not a permanent guarantee of enrolment or identity.
- Survey creators control their questions and may ask respondents for identifying information. Respondents should review each survey before submitting.
- No online service can promise that unauthorized access, human error, service interruption, or abuse will never occur.
- Privacy and security controls require ongoing review as the service, its providers, and legal requirements change.
Data flow
- Account and profile information is collected during registration and stored in the protected database.
- Survey creators define questions and audiences; eligible respondents submit answers through signed-in accounts or authorised invitation paths.
- Responses are stored for the survey owner’s analysis. Access links and progress permissions are separately controlled.
- Paystack processes checkout details and reports payment status; CampusVerify records the transaction reference and resulting credits or service.
- Expected app emails are sent for account and feature events. The sending domain is not an incoming mailbox.
Contact and review
Operator: Vibe Tribe Organisation, Ghana. Privacy or security questions can be sent to campusverify996@gmail.com.
Read the Privacy Policy