Skip to content
Security

Student data deserves serious protection.

Security at ClassSynk isn’t a feature you pay extra for. It is how every part of the platform was built, from sign-in to the audit trail.
Sign-in

Three checks before anyone gets in.

Every sign-in, on the dashboard and on the app, passes all three. A leaked password on its own opens nothing.

Password

Checked against rules that match the server exactly.

One-time code

A fresh code is emailed for every sign-in.

One session

Any older session on another device ends.

Protections

Twelve layers, on every plan.

Two-step sign-in

Everyone signs in with a password and a one-time code sent to their email. A stolen password alone is not enough.

Invite-only accounts

Nobody can sign themselves up. Every account starts as an invite from your institution, with a link that works once and expires in 24 hours.

One active session

Signing in on a new device signs out the old one, and a password reset ends every session. A forgotten, logged-in computer stays safe.

Role-based access

Admins, teachers, students and families each see only what their role allows, and every request is checked on the server.

Your data stays yours

Every record belongs to one institution, and every request is checked against it. No institution can ever see another’s data.

A complete audit trail

Registrations, attendance, exam milestones, announcements and alerts are all recorded with who did what and when.

Mark-level history

Every change to a student’s marks is kept, including re-evaluation and moderation, so results can always be explained.

Short-lived access

Access tokens expire quickly and are never written to the browser’s storage. Sessions renew quietly while you work.

Codes that can’t be guessed

A code works once, five wrong guesses cancel it, and how often new codes can be sent is limited.

Several admins, each accountable

An institution can have several admins, each with their own sign-in, so every action on record belongs to a person.

Blocked means blocked

An account your institution blocks is refused at sign-in, on the dashboard and on the app.

Location only at check-in

Teacher check-in reads the phone’s location at the moment of checking in. ClassSynk doesn’t follow teachers through the day.

Accountability

Every important action, on the record.

When a parent asks why a mark changed or who sent a notice, the answer is already there: who did it, what changed and when.

Our commitments

  • Your data belongs to your institution

  • We never sell student or staff data

  • Data is used only to run ClassSynk for your institution

  • Accounts exist only because your institution invited them

Protecting what’s coming

The most sensitive data, protected from day one.

Some planned modules will hold health records, bank details, private messages and live locations. Here’s how they’ll protect them.
Planned

Health and bank details, encrypted

Health records and staff bank details stored encrypted, visible only to the people who need them, with every view recorded.

Planned

Messaging the school can review

The school’s admins can read parent–teacher conversations, and every read is recorded.

Planned

Bus locations for the right families

A bus’s live location is shared only with the families on that route, and old location data is deleted.

Have a security question?

We are happy to walk your management or IT team through how ClassSynk protects your data. Write to privacy@classsynk.com.

See ClassSynk running with your own data.

Book a 30-minute demo. We will walk you through the dashboard and the app, and show you how quickly your institution can be live.