Skip to main content
SchoolStacker Logo

Security & Data Protection Standards

How we protect student records, institutional configurations, and financial data.

Enterprise-Grade Security Architecture

School Stacker is built on the principle of defense-in-depth. Educational data is highly sensitive, comprising student health histories, academic transcripts, family contacts, and financial records. We employ strict database isolation, network encryption, and constant monitoring to secure your environment.

Core Security Safeguards

1. Database Schema Isolation

Unlike traditional multi-tenant databases that pool all customer records into shared tables, School Stacker isolates every school workspace at the virtual schema level.

  • Strict Logical Boundaries: Database connection pools execute within strict tenant constraints, preventing cross-tenant queries under any condition.
  • Separate Encryption Keys: Individual tenant schemas can be encrypted with distinct cryptographic keys, providing double-layered protection.
  • Zero Data Leakage: A vulnerability in one school's customized dashboard configuration cannot expose the records of another campus.

2. Data Encryption Standards

We encrypt your data at every state: in transit, in memory, and at rest in our cloud storage systems.

  • In Transit: All web and API traffic is encrypted using TLS 1.3. Standard HTTP requests are automatically redirected to secure HTTPS endpoints. We enforce HTTP Strict Transport Security (HSTS).
  • At Rest: Databases, logs, backups, and file attachments are encrypted using industry-standard AES-256 algorithms. Cryptographic keys are rotated automatically.

3. Regulatory Compliance

School Stacker conforms to global and regional educational and data protection standards:

FERPA Compliance

Fully aligned with the Family Educational Rights and Privacy Act. Student information is disclosed only to authorized school officials and legal parents/guardians.

GDPR & Local Regulations

Compliance with the General Data Protection Regulation and regional regulations. We act as data processor, empowering schools to support user right-to-erase claims.

Infrastructure & Disaster Recovery

Continuous Vulnerability Scans

Our hosting infrastructure is scanned hourly for package vulnerabilities, security misconfigurations, and unauthorized access attempts. Intrusion detection systems (IDS) monitor API traffic anomalies, instantly alerting our security operations center (SOC).

High Availability & Backups

We run redundant servers across separate cloud availability zones.

  • Hourly Snapshots: School databases are backed up automatically every hour. Backups are stored in separate, geographically isolated object storage.
  • Point-in-Time Recovery (PITR): In case of accidental admin deletion or service disruptions, databases can be restored to a specific minute within the previous 35 days.
  • SLA Commitment: Supported by our 99.9% uptime availability guarantee, keeping school administration online.

Responsible Disclosure

If you discover a security vulnerability or have questions about our data safety guidelines, please email our security response team directly at info@stemlen.com. We investigate all claims and coordinate solutions quickly.