Encryption everywhere
TLS 1.3 on every connection. AES-256 on the database and on every backup. Nothing about a child travels or rests in plain text.
Children's data. We take it seriously. Here is exactly what we do, in plain language.
The security comes from how the platform is built — not where the wires happen to be. Here is what protects your school's data on every request, every day.
TLS 1.3 on every connection. AES-256 on the database and on every backup. Nothing about a child travels or rests in plain text.
Teachers see their classes. Parents see their children. Headmasters see their school. Nobody — including us — sees more than they should.
Every login, every edit, every export is logged with a timestamp and a signature. Exportable for MoE inspections.
We host on tier-1 cloud infrastructure — the same standard the world's largest schools and hospitals use.
Hosted in audited datacenters with independent third-party security certification. Physical access controls, network segmentation, 24/7 monitoring — handled by the host, not by us.
Backups every 24 hours, 30-day restore window. Snapshot restore is tested every quarter. If a school ever needs to roll back, we can.
Headmaster, teacher, parent, student — each role sees only what it should.
Your school cannot see another school’s data. Ever.
Every administrative action recorded. Exportable for inspection.
Parents see a clear, plain-Tetum consent record. They can request data export or deletion at any time, in line with GDPR-style norms.
TLS 1.3 on every connection. AES-256 on every database. Nothing about a child travels or rests in plain text.
Encrypted backups every night, retained 30 days. Snapshot restore tested every quarter.
A class teacher can’t see another class. A bursar can’t see grades. A parent only sees their own children.
Every administrative action signed and timestamped. Audit log is exportable for school inspection.
We collect only what a school needs to operate. No advertising trackers, no third-party SDKs.
Parents can ask their school to delete their child’s record at any time. The school can also delete the whole school’s account themselves.
In the unlikely event of a security incident, we follow a published playbook. Within 24 hours we identify and contain. Within 72 hours we notify affected schools and any regulator we're required to inform. We publish a post-incident report once the incident is closed.
Our compliance team will answer in plain language.