SECURITY ROADMAP

School trust has to be engineered into the platform.

The production classroom application should treat security, privacy, access control, data isolation, and operational resilience as foundational architecture—not procurement paperwork added at the end.

PRODUCTION BASELINE

Security controls planned for the classroom platform.

Encryption

TLS in transit, encryption at rest, and secure secret management.

Authorization

Role-based permissions for students, teachers, administrators, and internal staff.

Tenant isolation

Server-side school scoping so one school cannot retrieve another school’s resources.

Audit logging

Record sensitive administrative and staff access without placing raw student content in routine logs.

Resilience

Backups, restoration testing, rate limiting, dependency scanning, and incident-response procedures.

Administrative security

MFA for sensitive internal/admin functions and controlled access to production systems.

DATA LIFECYCLE

Collect less. Keep it only as long as the educational purpose requires.

Collect minimum necessary dataUse for authorized educational serviceRestrict accessSupport school export / deletionExpire according to retention policy
SCHOOL DOCUMENTATION

Planned trust-center materials.

Security OverviewSubprocessor ListIncident ResponseRetention & DeletionAccess ControlsAI Transparency

These are roadmap commitments, not claims that every document or control is already production-complete.

SCHOOL REVIEW

Have security or procurement requirements for a pilot?

Contact Splash