EARLY ACCESS

Cloud security & privacy

Protect the mobile interface without weakening the campus record.

The cloud will receive only information required for approved mobile functions. It will not become an uncontrolled copy of every campus table.

Planned controls

Security across identity, mobile, cloud, gateway, and campus boundaries.

EARLY ACCESS

No direct database exposure

Mobile apps use a secured API. SQL Server is not published to the internet.

EARLY ACCESS

Tenant and campus isolation

Every authorization decision is evaluated within the approved tenant, campus, role, and relationship scope.

EARLY ACCESS

Institution-approved account linking

A successful login does not by itself prove guardianship, student access, employment, or class assignment.

EARLY ACCESS

Unique gateway identity

Each campus gateway receives revocable, rotatable credentials bound to the approved campus.

EARLY ACCESS

Purpose-limited projections

Only fields required for approved mobile functions are synchronized.

EARLY ACCESS

Short-lived sessions

Access tokens, refresh behavior, device/session revocation, and strong authentication reduce account risk.

EARLY ACCESS

Payment verification

Provider webhooks are authenticated and transactions are independently verified before campus posting.

EARLY ACCESS

Audit and correlation

A workflow can be traced from mobile request through cloud, gateway, campus transaction, and final result.

EARLY ACCESS

Signed software delivery

Gateway installers and updates will use controlled, versioned, signed distribution.

EARLY ACCESS

Privacy-safe telemetry

Logs and monitoring exclude secrets and avoid unrestricted student, report, or payment payloads.

EARLY ACCESS

Children-specific safeguards

Production launch requires approved privacy, security, retention, and relationship controls for children’s records.

EARLY ACCESS

Incident readiness

Operational status, restricted security tickets, escalation, and response procedures will be prepared before launch.

Governance before launch

Privacy and data location are architecture decisions.

Before production, CABS will complete appropriate review of children's information, academic and financial data, retention, cross-border processing, third-party providers, incident response, data-subject rights, and institutional contracts.

Development boundary

This page describes the accepted security design. It does not claim that the cloud platform is already processing production school data.

Institutional readiness

Include security and privacy owners in the pilot.

The pilot application captures technical and privacy contacts so that mobile access is not treated as a purely cosmetic app rollout.

Apply for Pilot Review
Chat on WhatsApp