Enterprise-Grade Security & Compliance

Secure, Compliant & Trusted

Your data security and privacy are our top priorities. Built with enterprise-grade security for IB schools worldwide.

GDPR Compliant

Full compliance with EU data protection regulations. Your school data stays private and secure.

  • Right to access, rectify, and delete data
  • Data processing agreements available
  • EU data residency options
  • Transparent data handling practices

End-to-End Encryption

Bank-level AES-256 encryption for all data in transit and at rest. Your information is always protected.

  • AES-256 encryption at rest
  • TLS 1.3 for data in transit
  • Encrypted database backups
  • Secure API communications

ISO 27001 Certified

International standards for information security management. Audited and verified annually.

  • Annual third-party audits
  • Documented security policies
  • Risk assessment procedures
  • Continuous improvement process

FERPA Compliant

Meets US student privacy regulations. Safe handling of educational records and student data.

  • Student record protection
  • Parental consent mechanisms
  • Limited data sharing controls
  • Audit trail for data access

Security Measures

Multi-layered protection to keep your school's data safe and accessible

Infrastructure Security

Enterprise-grade hosting with redundancy and disaster recovery

  • Multi-region data centers
  • Automatic daily backups
  • 99.9% uptime SLA
  • DDoS protection

Access Control

Role-based permissions ensure only authorized users can access data

  • Multi-factor authentication (2FA)
  • Role-based access control (RBAC)
  • Session management
  • IP-based access restrictions

Data Privacy

Your data is yours - we never share, sell, or use it for other purposes

  • No third-party data sharing
  • Data isolation per school
  • Privacy by design
  • Transparent data usage

Certifications & Compliance

Independently verified and audited security standards

GDPR
Compliant
SOC 2 Type II
Aligned
ISO 27001
Aligned
FERPA
Aligned
COPPA
Aligned

GDPR compliance is mandatory under EU law. SOC 2 and ISO 27001 controls are mapped to our infrastructure but we are not formally audited yet — see our detailed controls summary on the Security page. FERPA and COPPA are US-specific frameworks; we apply the equivalent privacy principles, but US schools should request our written compliance statement for those. View detailed Security & Compliance controls

Our Data Handling Principles

Data Minimization

We only collect and store data necessary for scheduling operations. No unnecessary personal information is gathered or retained.

Data Isolation

Each school's data is completely isolated with row-level security. Schools cannot access or view data from other institutions.

Data Retention

You control your data. Export anytime, delete on request. We retain data only as long as your subscription is active (plus legally required periods for billing records).

Transparency

Clear audit logs show who accessed or modified data. No hidden data usage. Full transparency in how we process scheduling information.

No AI Training on Your Data

Your school data is never used to train AI models. All scheduling algorithms operate on your data in isolation without contributing to external model training.

Questions About Security?

Our security team is here to address any concerns or questions about data protection, compliance, or our security practices.

Contact Security Team

We use only strictly-necessary cookies (auth + security). No analytics, no tracking, no advertising. Full inventory →