Skip to content

Security

School trust is a product requirement.

Security is designed into tenant access, permissions, financial transitions and operational audit trails—not left to frontend visibility rules.

Tenant isolation

Every school is treated as an independent tenant. Tenant-owned operations use the authenticated school context.

Role-based access

SuperAdmin, School Admin, Teacher, Student and Parent workflows have separate authorization boundaries.

Payment integrity

Amounts are calculated by the server and money is credited only after signed gateway confirmation.

Session protection

Refresh sessions, revocation and protected routes reduce unauthorized access risk.

Auditability

Sensitive operational changes and financial transitions produce audit records.

Responsible launch

Backups, monitoring, provider UAT and restore testing remain mandatory before production activation.

VidyaLynq