Your school's data is sacred.
We treat learner, staff and parent information the way a doctor treats a medical record. Here's exactly how.
Encryption everywhere
TLS 1.2+ in transit. AES-256 at rest. Biometric templates encrypted on-device where possible.
Row-Level Security
Every query scoped by school_id and role at the database. Cross-tenant leakage is structurally impossible.
Strong authentication
Email + magic link, optional SSO, password rules and forced 2FA for staff with grade-edit rights.
Tamper-evident audit
Every login, mark change, fee waiver and export is hash-chained and unmodifiable — aligned with the Data Protection Act 2021.
DSAR workflow
Data Subject Access Requests handled in-app with response packs auto-drafted from the audit trail.
Least privilege
Roles & permissions matrix enforced everywhere. Bursars see finance, teachers see their classes, parents see their children.
Resilient infrastructure
Encrypted nightly backups, point-in-time restore, multi-region failover, daily restore drills.
Anomaly detection
AI flags late-night bulk mark edits, fee-waiver clusters and unusual login patterns to the school head.
Retention schedule (excerpt)
| Record class | Retention |
|---|---|
| Learner academic record | 10 years post-graduation |
| Discipline incident log | 7 years |
| Financial books | 10 years (ZIMRA) |
| Biometric templates | While enrolled + 90 days |
| Audit log | 7 years (immutable) |
| SDC / Board minutes | Permanent |
Responsible disclosure
Found a vulnerability? Email tichremias@nalietech.com with reproduction steps. We acknowledge within 48 hours and aim to resolve critical issues in under 7 days. Good-faith researchers are protected from legal action.
