Security & Privacy

Your school's data is sacred.

We treat learner, staff and parent information the way a doctor treats a medical record. Here's exactly how.

Encryption everywhere

TLS 1.2+ in transit. AES-256 at rest. Biometric templates encrypted on-device where possible.

Row-Level Security

Every query scoped by school_id and role at the database. Cross-tenant leakage is structurally impossible.

Strong authentication

Email + magic link, optional SSO, password rules and forced 2FA for staff with grade-edit rights.

Tamper-evident audit

Every login, mark change, fee waiver and export is hash-chained and unmodifiable — aligned with the Data Protection Act 2021.

DSAR workflow

Data Subject Access Requests handled in-app with response packs auto-drafted from the audit trail.

Least privilege

Roles & permissions matrix enforced everywhere. Bursars see finance, teachers see their classes, parents see their children.

Resilient infrastructure

Encrypted nightly backups, point-in-time restore, multi-region failover, daily restore drills.

Anomaly detection

AI flags late-night bulk mark edits, fee-waiver clusters and unusual login patterns to the school head.

Retention schedule (excerpt)

Record classRetention
Learner academic record10 years post-graduation
Discipline incident log7 years
Financial books10 years (ZIMRA)
Biometric templatesWhile enrolled + 90 days
Audit log7 years (immutable)
SDC / Board minutesPermanent

Responsible disclosure

Found a vulnerability? Email tichremias@nalietech.com with reproduction steps. We acknowledge within 48 hours and aim to resolve critical issues in under 7 days. Good-faith researchers are protected from legal action.