Trust · Schoolyi Security
Security at Schoolyi
Encryption, role-based access, audit logs, and secure development for K-12 data on Schoolyi. What IT and procurement should verify.
https://security.schoolyi.com · Schoolyi - Cloud School Management System (SMS)
Defense in depth, not checkbox marketing
A school ERP breach erodes parent trust for years. Schoolyi scopes access by role and assignment - a homeroom teacher sees their classes, finance sees fee ledgers, parents see linked children only. That scoping is enforced server-side on every request, not hidden behind UI menus.
Encryption and transport
Traffic uses HTTPS in transit. Credentials are hashed; sessions expire per policy. File uploads for admissions documents and staff records inherit the same transport protections as gradebook data.
- TLS for browser and API traffic
- Password hashing with industry-standard algorithms
- Optional SSO for centralized identity control
- Secure cookie settings for session management
Access control and audit
Permission matrices map modules to roles - registrar, bursar, teacher, parent. Sensitive exports and bulk downloads should be limited to roles that need them. Activity logs help investigators answer who changed a fee waiver or published report cards.
Secure development lifecycle
Changes pass code review and automated checks before release. Dependencies are monitored; critical patches ship on a defined cadence. Feature flags let schools enable modules gradually rather than exposing half-configured workflows.
Hosting and segmentation
Production workloads run on managed cloud infrastructure with network segmentation between application and data tiers. Backups and restore procedures are tested. Data residency options are documented per deployment region for international buyers.
What schools should configure
Strong password policy, limited admin accounts, and regular review of role assignments after staff turnover. Disable ex-employee access the day they leave - HR offboarding and IT access review should be the same ticket.
Reporting security concerns
Schools and researchers can report vulnerabilities through the published security contact. We acknowledge reports and coordinate disclosure timelines with affected customers when necessary.
Platform module
See capabilities and outcomes
Screenshots, highlights, and team workflows on the main Schoolyi site.
View moduleOn schoolyi.com
Browse the full resource
This subdomain hub links to the canonical resource on www.
Open resource- Role-based access - teachers, finance, admissions, and families see scoped workspaces
- One academic calendar drives attendance, exams, fees, and leave
- Phased rollout: admissions, roster, and fees first - expand when teams are ready
Guides
Learn more about schoolyi security
Guide
Getting started with schoolyi security
A practical primer for school leaders evaluating schoolyi security - scope, stakeholders, and what to demo first.
Read guideGuide
Implementing schoolyi security without a rip-and-replace project
How phased rollout keeps security live while teams adopt Schoolyi module by module.
Read guideGuide
Schoolyi Security readiness checklist
Use this checklist before you sign or before go-live week for schoolyi security.
Read guide
Frequently asked questions
Common questions about schoolyi security with Schoolyi - Cloud School Management System (SMS).
Is data encrypted at rest?+
Database and object storage use provider-managed encryption at rest. Details appear in the security summary for procurement questionnaires.
Can we export activity logs?+
Yes. Admins with audit permissions can export logs for investigations and compliance reviews.
How does Schoolyi handle ex-staff access?+
Deactivate the staff record and linked user account. Role assignments drop immediately; historical audit entries retain the user identity for traceability.
Related hubs
Explore more Schoolyi subdomains
trust.schoolyi.com
Trust center - privacy, security, and compliance
Privacy, security, subprocessors, and DPA resources for schools evaluating Schoolyi. Documentation procurement teams expect before go-live.
Visit hubcompliance.schoolyi.com
Compliance for school data
GDPR-oriented workflows, FERPA-aware access scoping, and retention guidance for schools using Schoolyi internationally.
Visit hubit.schoolyi.com
School IT without becoming the integration department
Role-based access, bulk provisioning, activity logs, cloud hosting, imports, and API hooks for school IT - one student ID across modules.
Visit hub

See schoolyi security in a live SMS walkthrough
We show how this capability fits your cloud school management system - and which teams should go live first.
Already using Schoolyi? Sign in
