Security Practices

We protect student and staff data using industry-aligned controls. This page outlines the safeguards implemented across our school management platform.

1 Access Control

  • Role-based permissions ensure users only access features relevant to their responsibilities.
  • Session management enforces secure login flows and automatic expiration on inactivity.
  • Multi-factor authentication can be enabled for administrators and high-privilege roles.

2 Data Protection

  • Sensitive fields such as passwords and personal identifiers are stored using strong hashing or encryption.
  • All file uploads are scanned for malicious content and stored in restricted directories.
  • Regular database backups are encrypted and tested for integrity.

3 Monitoring & Auditing

  • Audit logs record administrative actions, grade changes, and login events to support investigations.
  • Automated alerts notify school leadership about suspicious activity or repeated login failures.
  • Routine reviews of access logs help identify inactive accounts and potential insider threats.

4 Incident Response

  • Established procedures guide containment, notification, and recovery in the event of a security incident.
  • Designated contacts coordinate with school leadership and parents when student data may be affected.
  • Post-incident reviews ensure lessons learned are integrated into future safeguards.

5 Best Practices for Users

  • Keep passwords unique, complex, and private. Change them if you suspect exposure.
  • Log out from shared devices and report unusual behavior to school administrators.
  • Use approved browsers and keep software up to date to reduce vulnerabilities.

6 Security Contacts

If you notice a security concern, contact the school administration or email sasjubba@email.com. We respond promptly to safeguard student data.