Security Practices
We protect student and staff data using industry-aligned controls. This page outlines the safeguards implemented across our school management platform.
1 Access Control
- Role-based permissions ensure users only access features relevant to their responsibilities.
- Session management enforces secure login flows and automatic expiration on inactivity.
- Multi-factor authentication can be enabled for administrators and high-privilege roles.
2 Data Protection
- Sensitive fields such as passwords and personal identifiers are stored using strong hashing or encryption.
- All file uploads are scanned for malicious content and stored in restricted directories.
- Regular database backups are encrypted and tested for integrity.
3 Monitoring & Auditing
- Audit logs record administrative actions, grade changes, and login events to support investigations.
- Automated alerts notify school leadership about suspicious activity or repeated login failures.
- Routine reviews of access logs help identify inactive accounts and potential insider threats.
4 Incident Response
- Established procedures guide containment, notification, and recovery in the event of a security incident.
- Designated contacts coordinate with school leadership and parents when student data may be affected.
- Post-incident reviews ensure lessons learned are integrated into future safeguards.
5 Best Practices for Users
- Keep passwords unique, complex, and private. Change them if you suspect exposure.
- Log out from shared devices and report unusual behavior to school administrators.
- Use approved browsers and keep software up to date to reduce vulnerabilities.
6 Security Contacts
If you notice a security concern, contact the school administration or email sasjubba@email.com. We respond promptly to safeguard student data.