Security, privacy and accountability

Protect school access. Trace important activity. Handle data responsibly.

School information is sensitive. EduIntels uses layered application, access, session, audit, and school-context controls to support safer operations and NDPR-conscious data handling.

View platform overview
Role-based permissions Audit records Protected sessions
Security and control centre
Identity and access

Approved roles and school permissions

Controlled
Session protection

Secure cookies, CSRF tokens and session renewal

Protected
School data context

School-linked queries and permitted-school checks

Scoped
Operational traceability

Audit logs, login attempts and workflow history

Traceable
Continuity practices

Backups, document checksums and recovery planning

Managed
Layered controlsSecurity does not depend on one feature.
School-scopedOperational records are linked to school context.
Traceable actionsImportant events can be logged and reviewed.
Shared responsibilityTechnology and school practice must work together.
Defence in depth

Security is a system of controls, not a single switch.

EduIntels applies controls at identity, session, application, database, workflow, provider, and operational levels. The school must complement these controls with good user management, clear policies, and disciplined administration.

Security settings, administrator permissions, provider credentials, retention decisions, and user offboarding should be reviewed during implementation and periodically after go-live.

Identity and permissions

Password hashing, active-user checks, role assignment, permitted-school access, and controlled administrator functions.

Session and form protection

HTTP-only cookies, SameSite settings, secure-cookie detection, token validation, and session regeneration.

Database safety

Prepared statements, scoped records, validated identifiers, and module-level access checks reduce unsafe data access.

Audit and monitoring

Login attempts, audit logs, workflow histories, provider events, print records, and verification logs support investigation.

Integration controls

Provider secrets, callback verification, webhook signature checks, event deduplication, and processing status records.

Document integrity

Public references, snapshots, checksums, controlled downloads, version history, and expiration can protect generated records.

Access governance

Give users enough access to do their work, but no more than necessary.

Role-based access should reflect real responsibilities. A bursar does not need the same controls as a teacher. A school administrator should not automatically have unrestricted platform authority. Owners, branch administrators, staff, and operational users should be assigned carefully.

Approved users Least privilege School context Reviewable actions
User lifecycle

Create accounts deliberately, verify responsibilities, suspend inactive access, and remove former staff promptly.

Permission review

Review sensitive permissions whenever roles, departments, branches, or reporting lines change.

Credential discipline

Use strong unique passwords, protect email accounts, avoid shared logins, and secure administrator devices.

Exception review

Investigate unusual sign-ins, repeated failures, unexpected changes, failed integrations, and unauthorised access attempts.

Privacy governance

NDPR-conscious technology still requires responsible school policies.

Privacy is not solved by software alone. The institution remains responsible for defining what information it collects, why it collects it, who may access it, how long it is retained, and how data-subject requests are handled.

Schools should obtain professional legal or data-protection advice for their specific obligations, notices, contracts, retention schedules, and incident-response arrangements.

Purpose limitation

Collect and use personal information only for clear, legitimate, and communicated school purposes.

Data minimisation

Avoid collecting unnecessary fields and restrict access to sensitive information.

Retention control

Define how long different records should remain active, archived, exported, or securely removed.

Data-subject rights

Create a process for access, correction, objection, deletion, or other valid requests where applicable.

Transparent notices

Inform staff, parents, guardians, and students about data use in language they can understand.

Incident response

Define escalation, containment, investigation, communication, documentation, and recovery responsibilities.

Control summary

Understand what each layer contributes.

Control areaEduIntels approachSchool responsibility
AuthenticationPassword hashing, session renewal, login-attempt controls, remember-token handling.Protect accounts, email access, devices, and password practices.
AuthorisationRoles, permissions, school membership, selected-school context, and access checks.Approve correct roles, review access, and offboard users promptly.
Application protectionCSRF validation, input handling, prepared database statements, and secured internal folders.Use supported browsers, avoid unsafe modifications, and maintain hosting securely.
AuditabilityAudit logs, workflow history, provider events, verification logs, and document history.Review exceptions, investigate anomalies, and retain evidence appropriately.
PrivacyScoped access and NDPR-conscious platform design.Define lawful basis, notices, retention, rights handling, and institutional policy.
ContinuityBackup practices, versioned records, document snapshots, checksums, and recovery planning.Agree backup frequency, test recovery, retain exports, and define continuity roles.
Security questions

Clear answers without impossible promises.

Does EduIntels use role-based access?
Yes. Access can be assigned according to approved roles and school responsibilities so that users work within the functions and records permitted for them.
How are sign-in sessions protected?
The application uses secure session practices, HTTP-only cookies, SameSite controls, session regeneration after authentication, login-attempt tracking, and expiring remember-me tokens.
How does EduIntels protect forms and database operations?
Sensitive form actions use CSRF validation, while database access uses prepared statements. Important administrative and operational activities can also be recorded in audit logs.
Is EduIntels NDPR compliant?
EduIntels is designed with NDPR-conscious data-handling practices. Formal compliance also depends on the school’s policies, lawful basis, notices, user permissions, retention decisions, contracts, and operational discipline.
Can different schools see one another’s records?
The platform uses school context and school-linked access checks across operational modules. Permissions and implementation configuration must still be reviewed carefully during onboarding.
Does the platform guarantee that no security incident can occur?
No responsible technology provider can promise absolute security. EduIntels applies layered controls and ongoing operational practices to reduce risk, detect issues, and support responsible response.
Review your control requirements

Request a security and privacy walkthrough for your school.

Discuss user roles, branch access, administrator permissions, provider credentials, audit requirements, privacy responsibilities, backup expectations, and implementation controls.

Explore integrations