Security that supports your mission

Security is foundational to everything we do. We follow rigorous data protection standards because we know trust is essential as we support your school and the families you serve.

The Six Principles That Guide Our Approach:

Security By Default

We build security into every system from the start, so protection is always on and never optional.

Minimized Access

We strictly limit access to what’s necessary for stakeholders to execute their primary responsibilities. That means reduced risk and strengthened data confidentiality.

Continuous Monitoring

We continuously monitor our infrastructure with automated detection systems and routine human checks to identify anomalies and respond to threats in real-time.

Encrypted Everything

Data is encrypted in transit and at rest to keep user information secure and unreadable.

Transparency & Trust

Our security practices, incidents and updates are openly shared with customers and partners because we believe a trusting and resilient relationship is built on transparency.

People-First Security

We prioritize human-centric design and communication to make secure behavior the easiest and most natural choice for every user.

People & Process Security

Product Security
Access Controls
Granular, role-based permissions ensure users and systems can only access what they’re authorized to, reducing risk across the platform.
Secure SDLC and Code Review
Security is embedded throughout the development lifecycle, including automated static analysis and peer review for all changes.
Regular Penetration Testing
Independent third-party security assessments are conducted routinely, with findings remediated promptly.
Secure Document Sharing
Sensitive PDFs are shared through auto-expiring links to reduce long-term exposure. Families can’t access documents they’ve already submitted to the school, preventing accidental re-exposure of private information.
Vulnerability Management and Patch Discipline
Dependencies and infrastructure are regularly scanned and patched to minimize exposure to known threats.
Comprehensive Logging and Monitoring
Full audit trails and real-time alerts are in place to detect misuse or breach attempts immediately.
User Security
Single Sign-On (SSO), MFA and Account Protection
Mandatory multi-factor authentication for school users to protect against brute force, phishing, and credential stuffing.
Least Privilege by Default
Users only see and do what is necessary for their role or context, minimizing accidental exposure.
Granular In-App Permissions
Schools can define exactly which of their users can view or manage specific data, using flexible, fine-grained permissions built directly into the platform.
Household Security
Each household’s data is private and separate. Even when households share a student, they can’t see each other’s information, keeping financial aid, contracts, and billing secure.
Security-Focused UX
Prompts and defaults are designed to nudge users toward secure behavior without adding friction.
User Education and Transparency
Users are informed about how to protect themselves, what to expect, and how the platform keeps them safe.
Data Privacy
Transparent Privacy Practices
Privacy policies are clear, accessible, and kept up-to-date, with mechanisms for users to control their data.
Data Minimization
Only the data required to deliver value is collected, stored, and processed.
End-to-End Encryption
All data is encrypted in transit and at rest, using strong, industry-standard protocols.
Purpose Limitation
Data is used strictly for its intended purpose, with safeguards to prevent misuse or secondary use.
Retention and Deletion Policies
Data is retained only as long as needed and deleted securely upon request or inactivity.
Third-Party Risk Management
Vendors with access to data are vetted, monitored, and contractually bound to equivalent privacy standards.

Trusted by 1200+ of your peers schools

Have a Security Question?

Whether you have a question or just want to learn more about our best-in-class security for schools, we'd love to connect.

Get in touch