Skip to main content

Trust · Schoolyi Security

Security at Schoolyi

Encryption, role-based access, audit logs, and secure development for K-12 data on Schoolyi. What IT and procurement should verify.

https://security.schoolyi.com · Schoolyi - Cloud School Management System (SMS)

Defense in depth, not checkbox marketing

A school ERP breach erodes parent trust for years. Schoolyi scopes access by role and assignment - a homeroom teacher sees their classes, finance sees fee ledgers, parents see linked children only. That scoping is enforced server-side on every request, not hidden behind UI menus.

Encryption and transport

Traffic uses HTTPS in transit. Credentials are hashed; sessions expire per policy. File uploads for admissions documents and staff records inherit the same transport protections as gradebook data.

  • TLS for browser and API traffic
  • Password hashing with industry-standard algorithms
  • Optional SSO for centralized identity control
  • Secure cookie settings for session management

Access control and audit

Permission matrices map modules to roles - registrar, bursar, teacher, parent. Sensitive exports and bulk downloads should be limited to roles that need them. Activity logs help investigators answer who changed a fee waiver or published report cards.

Secure development lifecycle

Changes pass code review and automated checks before release. Dependencies are monitored; critical patches ship on a defined cadence. Feature flags let schools enable modules gradually rather than exposing half-configured workflows.

Hosting and segmentation

Production workloads run on managed cloud infrastructure with network segmentation between application and data tiers. Backups and restore procedures are tested. Data residency options are documented per deployment region for international buyers.

What schools should configure

Strong password policy, limited admin accounts, and regular review of role assignments after staff turnover. Disable ex-employee access the day they leave - HR offboarding and IT access review should be the same ticket.

Reporting security concerns

Schools and researchers can report vulnerabilities through the published security contact. We acknowledge reports and coordinate disclosure timelines with affected customers when necessary.

Platform module

See capabilities and outcomes

Screenshots, highlights, and team workflows on the main Schoolyi site.

View module

On schoolyi.com

Browse the full resource

This subdomain hub links to the canonical resource on www.

Open resource
  • Role-based access - teachers, finance, admissions, and families see scoped workspaces
  • One academic calendar drives attendance, exams, fees, and leave
  • Phased rollout: admissions, roster, and fees first - expand when teams are ready

schoolyi.com · full sitemap

Frequently asked questions

Common questions about schoolyi security with Schoolyi - Cloud School Management System (SMS).

Is data encrypted at rest?+

Database and object storage use provider-managed encryption at rest. Details appear in the security summary for procurement questionnaires.

Can we export activity logs?+

Yes. Admins with audit permissions can export logs for investigations and compliance reviews.

How does Schoolyi handle ex-staff access?+

Deactivate the staff record and linked user account. Role assignments drop immediately; historical audit entries retain the user identity for traceability.

Students walking together on a school campus

See schoolyi security in a live SMS walkthrough

We show how this capability fits your cloud school management system - and which teams should go live first.

Already using Schoolyi? Sign in