Karo
Safe. Simple. Sorted.
Karo Digital Classics Ltd
Version 1.0 · Last updated 15 August 2026
This assessment was carried out by Classic Talent Optimization at the request of Karo Digital Classics Ltd. Classic Talent Optimization is an affiliated party. This report is therefore an internal assurance exercise carried out to a defined method, and it is not, and is not presented as, an independent third-party penetration test or a certification.
It is published so that a school, a school's lawyer or a supervisory authority can see the method used, the scope covered and the findings, rather than taking an unevidenced assurance on trust.
Scope covered the hosted Karo platform in full: authentication and session handling, tenant isolation, row-level security across every table in the application schema, privileged console and impersonation paths, server functions and public API routes, tokenised document links, payment and settlement flows, file storage buckets, retention and purge jobs, and dependency supply chain.
Method combined authenticated role-by-role review against the permission matrix, automated cross-tenant test execution in the build pipeline, database policy and grant linting, static review of server-side entry points for input validation and authorisation, entropy review of every public tokenised link, and automated dependency and platform vulnerability scanning.
Findings were raised, fixed and re-tested during the review rather than left for a later cycle. The material classes were: cross-tenant reachability on a small number of server functions that took an identifier without re-scoping it to the caller's school; privileged read paths on the audit log that were broader than the role needed; missing table grants and policy gaps on newly added tables; unbounded resend and charge-initiation paths that allowed message and prompt spam; and document link generation that could race and issue a link before the document existed.
Every finding in those classes was closed and covered by a regression test that fails the build if it returns. Tenant isolation, permission gating and public link entropy were re-tested after remediation and passed.
The controls in place are appropriate for the platform's current stage, and no unresolved finding is known to be outstanding at the date of this report. The residual limitation is the standing of this report itself: the assessor is affiliated, so an externally commissioned test remains the stronger form of assurance and is intended before scaling materially beyond the current pilot footprint.
This report is reviewed at least annually, and after any change that affects authentication, tenant isolation, retention or the set of sub-processors.
Read alongside the incident response drill record.