Privacy & Security

How SchoolConnect protects school data

This page describes the security and privacy practices built into the platform today—school-scoped tenancy, role-based access, hashed credentials, audit visibility, and retention rules for sensitive media.

Back to overview

Secure Access & Transport

Hashed passwords, authenticated sessions, and HTTPS/TLS in production deployments.

Privacy Act Alignment

Designed to support K-12 schools operating under the Philippine Data Privacy Act of 2012.

School-Scoped Isolation

Each school is an independent tenant; data does not cross institutions.

Access and transport security

How accounts authenticate and how data moves across the network.

  • Staff, teacher, parent, and finance accounts authenticate with bcrypt-hashed passwords—credentials are never stored in plain text.

  • Authenticated sessions and role-based permissions control access to student records, billing ledgers, gradebooks, and uploaded materials.

  • Production deployments are intended to run over HTTPS/TLS. Laravel's AES-256-CBC cipher is available for application-level encryption where sensitive values require it.

  • Super Admin accounts can be required to enable two-factor authentication before accessing platform controls.

Regulatory alignment

How the platform supports schools' privacy obligations.

  • Platform practices are designed to support K-12 schools operating under the Philippine Data Privacy Act of 2012.

  • Schools retain ownership of their institutional data. SchoolConnect provides scoped workspaces—not a shared directory across institutions.

  • Platform-level actions—such as subscription changes, impersonation, and payment proof review—can be recorded in audit logs for operator review.

School-scoped data isolation

How tenants are separated across the platform.

  • Each registered school is an independent tenant. Academic, billing, and messaging data are scoped to that school throughout the application.

  • Data from one school is not visible to another. Additional campuses register as separate schools—not shared branches under one organization account.

  • Within a school, teachers are further scoped to assigned classes for uploads and roster-sensitive workflows.

Files and activity media

Retention and delivery rules for uploads and classroom photos.

  • Classroom activity photos are published to linked parents only and are automatically removed after 30 days.

  • Learning materials and payment proofs are stored in school-scoped paths and served through authenticated download flows—not open public directories.

  • Material visibility can be limited to the whole school, faculty only, or a specific class—depending on how staff publish the file.

Role-based access overview

A summary of who can reach sensitive areas inside a school workspace.

Student billing (own family)

Role: Parent Yes
Role: Finance Yes
Role: Admin Yes

Gradebook & progress

Role: Parent View
Role: Teacher Scoped
Role: Admin Yes

User & school settings

Role: Admin Yes
Role: Super Admin Via impersonation

Messages (Bridge)

Role: Parent Yes
Role: Teacher Yes
Role: Finance Yes
Role: Admin Yes
Role: Super Admin Yes

Platform schools & subscriptions

Role: Super Admin Yes

Questions or data requests

Reach our team for privacy inquiries or enterprise onboarding.

Ready to see it in your school?

Schedule a walkthrough to review access controls, workspace isolation, and day-to-day workflows with your registrar or IT team.