Security and data protection
Children's names, family contacts and payment records stay with each centre, seen only by the people who need them.
Each person sees their part
Owners see every branch, staff their own branches, teachers their classes and parents only their own children.
- Roles you can adjust
- Branch by branch
- Parents see their family only
Every change on record
Voids need a reason, unlocking attendance needs permission, and the log cannot be edited afterwards.
- Who, what, when and where
- Voids with their reasons
- Sign-ins and password changes
Built in, not added on
Kept apart from every other centre
Your records are separated from every other centre's by the database itself, not just by the app.
Row-level security in PostgreSQLAccess by role and branch
Staff see and change only what their role allows, in the branches they work in.
Role permissions, scoped per branchEvery change on record
Who changed what and when is kept, including voids with their reasons, sign-ins and password changes.
An audit trail that cannot be editedPasswords nobody can read
Passwords are stored one-way, and repeated failed sign-ins are blocked for a while.
bcrypt hashing, limited sign-in attemptsEncrypted connections
The console, the apps and this website are served over HTTPS only.
HTTPS with modern security headersBackups you can restore
The database is backed up continuously and can be restored to a chosen moment.
Point-in-time recovery, rehearsed restores
Questions from your IT team?
We are happy to go through how TuitionSync handles your data in detail.