Security architecture that supports trust. These are implementation details, not certification claims.
Separate school workspaces
Server-derived tenant context scopes school-owned records, reports and queries. Role-based permissions limit what accounts can do. Platform operators see aggregate school health rather than lesson routes or student details.
Traceable evidence
Route points, device events, audit events and reconciliation snapshots are append-only at the database level. Authorised corrections leave a reason and a recorded history. No system is described here as completely tamper-proof.
Sessions and transport
The platform includes rotating device refresh tokens, reuse detection, lockout controls, input validation, rate limiting and field encryption support. Production mobile apps require HTTPS. Deployment configuration and secret management are part of release readiness.
Report a concern
Send security questions to [email protected]. Do not include passwords, access tokens or sensitive student records in the initial email. The team can agree a suitable channel for details.