Security and data
Your school's records, kept as your school's records.
Schools hold money, results and children's details. This page says plainly how each of those is protected, and what we do not claim.
How it is built
Six controls, and what each one actually means.
One school cannot read another
Every table that belongs to a school carries the school it belongs to, and a database policy refuses rows from any other. Isolation is enforced under the application, so it holds even if a screen forgets to filter.
Roles decide what opens
Access is granted by role — principal, bursar, class teacher, store keeper, parent, learner and many more. A login only reaches the screens its role is allowed, and the sidebar only shows what it can reach.
Sensitive actions ask again
Deleting a receipt, reversing an invoice or offboarding a member of staff requires the person's password a second time, at the moment they do it.
The record says who did it
Sensitive actions are written to an activity log with the person, the time and what changed. Some finance screens record the device's location too, where the school has asked for it.
Books that cannot be quietly rewritten
A posted journal entry cannot be edited or deleted. Corrections are reversals carrying a reason, which is what an auditor expects to find in a ledger.
Credentials never sit in the school's reach
Vendor keys for messaging and payments are held by Rynedu, in tables no school client can read. A school subscribes to a channel; it never handles the key behind it.
Ownership
The data is the school's.
Rynedu operates the platform. What is in your workspace belongs to your school.
- You decide who has a login. Accounts are created by your principal or administrator, and removed by them.
- You decide what parents see. Publishing results, and any fee condition attached to them, is your school’s setting — not ours.
- You can take it with you. Registers, statements, ledgers and reports export from the screens that show them.
What we do not claim
The honest half of a security page.
Anything a school could check, we would rather state accurately than dress up.
- We do not claim a formal certification. If your board requires one, ask us where we are and we will tell you plainly.
- We do not claim any system is impossible to breach. We claim it is built so a mistake in one screen cannot expose another school’s data.
- We do not claim your staff cannot make errors. We claim the record will show who made them, and the books will show the correction rather than hide it.
Bring it to your board.We will answer the questions they ask.
Send us your data-protection requirements and we will respond against them point by point.
Already using Rynedu? Log in to your school