Security

Last updated: August 14, 2026

Schools trust Skolex with sensitive student, staff, and family data. This page describes the practices and controls we use to help keep that data safe.

1. Encryption

Data is encrypted in transit using industry-standard TLS. Passwords are never stored in plain text — they are hashed using strong, salted, one-way hashing algorithms, so we never have access to a user's actual password.

2. Access controls

Access to the Service is protected by authenticated, per-user accounts. Within a School, administrators control which staff can view or edit which records, following the principle of least privilege. Access to production systems and customer data by Skolex personnel is restricted to those who need it to operate and support the Service, and is logged.

3. Application security

We follow secure development practices, including input validation, parameterized database queries to prevent injection attacks, and code review before changes are deployed. Session authentication for administrative and account access uses signed, time-limited session tokens.

4. Infrastructure and hosting

The Service is hosted on infrastructure designed for reliability and security, with network-level protections in place to restrict unauthorized access to backend systems and databases. We aim to keep underlying platforms, frameworks, and dependencies up to date with security patches.

5. Backups and availability

We take regular backups of Customer Data to support recovery in the event of data loss or a service disruption, and design the Service with the goal of high availability for schools during operating hours.

6. Monitoring and incident response

We monitor the Service for irregular activity and errors. In the event of a security incident that affects personal data, we will investigate promptly and notify affected Schools without undue delay, consistent with our contractual and legal obligations, and will work with the School to determine any further notification that may be required.

7. Sub-processors and third parties

We rely on a limited number of reputable third-party providers for functions such as hosting, email delivery, and payment processing. These providers are given access only to the data necessary to perform their function and are bound by confidentiality and data protection obligations. See our Privacy Policy for more on how we share data.

8. Your role in keeping data secure

Security is a shared responsibility. Schools and their staff should use strong, unique passwords, avoid sharing login credentials, restrict staff access to only the records they need, and promptly remove accounts for staff who leave the School.

9. Responsible disclosure

If you believe you have discovered a security vulnerability in the Service, please report it to us at hello@skolex.online with the subject line "Security Report." Please include enough detail for us to reproduce the issue, and avoid accessing, modifying, or deleting data that does not belong to you. We will acknowledge reports promptly and work with you in good faith to investigate and resolve valid issues before any public disclosure.

10. Contact us

For questions about our security practices, contact us at hello@skolex.online.