Your data security matters. SchoolBench Pro is built with strong security controls, aligned with the control standards your school expects, to protect student and staff information.
Multiple layers of security protect your data at every level
The frameworks our security program follows for education data protection
SchoolBench Pro is fully compliant with the Family Educational Rights and Privacy Act (FERPA), ensuring the privacy and security of student education records.
We comply with the General Data Protection Regulation (GDPR) for our European users, giving individuals clear rights over their data and how it is used.
Our security program follows the SOC 2 Type II control standards covering security, availability, processing integrity, confidentiality, and privacy.
Our Information Security Management System (ISMS) is modelled on the ISO 27001 control standard.
Multiple layers of protection for your school's data
Our platform uses row-level security with complete data isolation between tenants (schools/districts), ensuring no cross-tenant data access.
Granular permission system with 100+ permission actions across all modules, ensuring users only access what they need.
Enhanced security with time-based one-time passwords (TOTP) and backup recovery codes to protect accounts from unauthorized access.
Support for Google Authenticator, Microsoft Authenticator, Authy, and other TOTP apps
10 single-use backup codes generated during 2FA setup for account recovery
Administrators can enforce 2FA for specific roles or all users
SSO integration with SAML 2.0 support, so users can sign in with their existing institutional credentials without managing a separate password.
Your data is encrypted both when stored and when moving between services, using the same protocols trusted by banks and governments.
Every action in the system is logged with a tamper-proof record, so you always know who did what and when.
Audit logs retained for 7 years with immutable storage and searchable interface
Automated daily backups with tested disaster recovery procedures so your school's data is safe if something goes wrong.
Maximum data loss in disaster scenario
Time to restore full service availability
We test our security regularly so problems are caught before they affect you
Third-party security assessments, conducted as needed, to identify and remediate vulnerabilities.
Continuous automated vulnerability scanning of infrastructure, applications, and dependencies with immediate remediation.
Static and dynamic code analysis integrated into our CI/CD pipeline to catch security issues before production.
How we keep your data safe, from development through to day-to-day operations
Security considerations at every stage of development
All code reviewed by security experts before deployment
Automated and manual security testing
Regular security awareness training for all staff
Principle of least privilege for all systems
24/7 incident response team and procedures
Have questions about our security practices? Our security team is here to help.
Contact Security Team