How we look after your team.
We hold a record of how your people are learning. That's personal, so Underwing is built the way we teach: assume someone is trying, and leave them nothing worth taking.
How to recognise us
Attackers borrow trusted names, and a security training company is an obvious one to borrow. This is what a real message from Underwing looks like, so a fake one has something to fail against.
Our email comes from hello@mail.underwing.co.za, and replies reach a person at @underwing.co.za. Read the address from the right: the name before .co.za is always exactly underwing. Our links go to underwing.co.za.
Sign-in links open a page that asks you to press a button. Nothing happens until you do.
Underwing will never ask for your password, a one-time code or new banking details. If a message claiming to be from us asks for any of these, it isn't from us.
Our banking details will never change by email.
Got something that claims to be from us and doesn’t fit? Don’t act on it. Forward it to security@underwing.co.za and we’ll tell you what it is.
How we protect your team
- No passwords, anywhere.
- Managers sign in with a single-use email link, then confirm with a passkey unlocked by their device's fingerprint, face or PIN. Learners never set a password. There's no password database to steal.
- Links that can't be replayed.
- Sign-in and learner links work once, expire quickly and are stored only as hashes, so even our own database can't be used to rebuild them.
- Locked-down pages.
- Every page carries a strict content security policy with a fresh code per request, so injected scripts can't run. We send the security headers browsers expect, everywhere.
- Limits on every door.
- Sign-in, sign-up and our public forms are rate-limited per connection and per address, and protected from bots.
- Payments we never touch.
- Card details are entered only on Paystack's checkout. We learn whether a payment worked from a signed message we verify before acting on it.
- A record of who did what.
- Sensitive actions are written to an append-only audit log. Network addresses in it are stored as keyed hashes, never in the clear.
- The least we can hold.
- For each learner: a name, a work email, an optional department and a score per field mark. Nothing else, deleted on schedule.
Where your data lives
Personal information is stored in South Africa, in Amazon Web Services’ Cape Town region. These are the companies that help us run Underwing, and what each one does:
| Company | What they do for us | Where |
|---|---|---|
| Amazon Web Services | Database and encrypted backups | South Africa (Cape Town, af-south-1) |
| Resend | Delivers our emails, such as sign-in links, lessons and reminders | Ireland (European Union) |
| Vercel | Hosts the website and application | Global edge network; server functions in Cape Town |
| Paystack | Card payments and subscriptions. Card details are handled only by Paystack. | Paystack's infrastructure, as set out in Paystack's privacy policy |
| Cloudflare | DNS, bot protection on forms (Turnstile) and video streaming. Videos contain no personal information. | Global network |
We’ll tell clients before we add or change a company on this list.
What managers can see
Managers see
- Who has completed each lesson
- Completion by department, for groups of five or more
- How the team reads each field mark
- How the team answered each challenge, as a total
- Who would benefit from a nudge, and why
- A monthly report and an evidence export for audits
Managers never see
- A list of who “failed”: we don’t keep one
- Individual answers in the free Team Spot Check
- Anything a learner didn’t do inside Underwing
Learners are told exactly what their manager can see before they start. Results are for learning, never for discipline, and our terms say so.
Assurance
- Independent penetration test
- Before launch and every year after. We'll share the summary with clients under NDA.
- POPIA
- We act as an operator for the learner information our clients give us, under a data processing agreement, and as a responsible party for our own customers' details.
- Security questionnaires
- We'll complete yours. Write to us and expect a person, not a portal.
- Certifications
- We don't hold an ISO 27001 or SOC 2 report yet, and we won't imply that we do. We're building to those controls.
Report a vulnerability
If you think you’ve found a security weakness in Underwing, please tell us at security@underwing.co.za. We’ll acknowledge your report within three working days and keep you updated until it’s fixed.
If you act in good faith, we won’t pursue legal action. That means: look only at what you need to show the problem, don’t access or change other people’s data, don’t degrade the service, and give us reasonable time to fix it before telling anyone else.
Our contact details are also published at /.well-known/security.txt.
Documents
Ready when your team is.