Security
Last updated: August 14, 2026
Schools trust Skolex with sensitive student, staff, and family data. This page describes the practices and controls we use to help keep that data safe.
1. Encryption
Data is encrypted in transit using industry-standard TLS. Passwords are never stored in plain text — they are hashed using strong, salted, one-way hashing algorithms, so we never have access to a user's actual password.
2. Access controls
Access to the Service is protected by authenticated, per-user accounts. Within a School, administrators control which staff can view or edit which records, following the principle of least privilege. Access to production systems and customer data by Skolex personnel is restricted to those who need it to operate and support the Service, and is logged.
3. Application security
We follow secure development practices, including input validation, parameterized database queries to prevent injection attacks, and code review before changes are deployed. Session authentication for administrative and account access uses signed, time-limited session tokens.
4. Infrastructure and hosting
The Service is hosted on infrastructure designed for reliability and security, with network-level protections in place to restrict unauthorized access to backend systems and databases. We aim to keep underlying platforms, frameworks, and dependencies up to date with security patches.
5. Backups and availability
We take regular backups of Customer Data to support recovery in the event of data loss or a service disruption, and design the Service with the goal of high availability for schools during operating hours.
6. Monitoring and incident response
We monitor the Service for irregular activity and errors. In the event of a security incident that affects personal data, we will investigate promptly and notify affected Schools without undue delay, consistent with our contractual and legal obligations, and will work with the School to determine any further notification that may be required.
7. Sub-processors and third parties
We rely on a limited number of reputable third-party providers for functions such as hosting, email delivery, and payment processing. These providers are given access only to the data necessary to perform their function and are bound by confidentiality and data protection obligations. See our Privacy Policy for more on how we share data.
8. Your role in keeping data secure
Security is a shared responsibility. Schools and their staff should use strong, unique passwords, avoid sharing login credentials, restrict staff access to only the records they need, and promptly remove accounts for staff who leave the School.
9. Responsible disclosure
If you believe you have discovered a security vulnerability in the Service, please report it to us at hello@skolex.online with the subject line "Security Report." Please include enough detail for us to reproduce the issue, and avoid accessing, modifying, or deleting data that does not belong to you. We will acknowledge reports promptly and work with you in good faith to investigate and resolve valid issues before any public disclosure.
10. Contact us
For questions about our security practices, contact us at hello@skolex.online.