INFORMATION SECURITY POLICY
Effective Date: 1/8/2026
Last Updated: 5/9/2026
1. Purpose
SchoolFlow recognises the importance of protecting customer, school, student, teacher and financial information.
This Information Security Policy establishes the general security principles used to protect SchoolFlow systems and information.
2. Security Principles
SchoolFlow seeks to maintain:
- Confidentiality;
- Integrity;
- Availability;
- Accountability; and
- Resilience of information and systems.
3. Access Control
Access to SchoolFlow systems should be restricted according to business need and user responsibilities.
Security controls may include:
- User authentication;
- Role-based access;
- Least-privilege principles;
- Administrative access restrictions;
- Account management; and
- Access revocation.
4. Password Security
SchoolFlow should maintain appropriate controls relating to:
- Password complexity;
- Password protection;
- Authentication;
- Account lockout or rate limiting where appropriate; and
- Credential security.
5. Encryption
Where technically implemented, sensitive information should be protected using appropriate encryption:
- During transmission; and
- At rest where appropriate.
Specific encryption standards should be documented internally based on the actual infrastructure.
6. Infrastructure Security
SchoolFlow infrastructure should be protected using appropriate measures such as:
- Firewalls;
- Network controls;
- Access restrictions;
- Security monitoring;
- System hardening;
- Vulnerability management; and
- Secure configuration practices.
7. Data Segregation
Where SchoolFlow operates as a multi-tenant SaaS platform, reasonable technical and organisational controls should be implemented to prevent unauthorised access between customer environments.
8. Logging and Monitoring
SchoolFlow may maintain logs relating to:
- Authentication;
- Administrative actions;
- Security events;
- System activity;
- Errors; and
- Other events necessary for security and operational purposes.
9. Backups
SchoolFlow should maintain appropriate backup mechanisms designed to support recovery from:
- Hardware failure;
- Software failure;
- Accidental deletion;
- Cybersecurity incidents; and
- Other operational disruptions.
10. Vulnerability Management
SchoolFlow should take reasonable steps to identify and address security vulnerabilities within its infrastructure and application.
11. Incident Response
In the event of a suspected security incident, SchoolFlow may:
- Identify and assess the incident;
- Contain the incident;
- Investigate its scope;
- Remediate affected systems;
- Restore affected services;
- Determine whether notification obligations apply; and
- Take preventative measures.
12. Employee and Contractor Security
Personnel with access to SchoolFlow systems should be subject to appropriate confidentiality and security obligations.
Access should be limited according to their responsibilities.
13. Secure Development
Where applicable, SchoolFlow development processes should incorporate:
- Code review;
- Secure coding practices;
- Dependency management;
- Testing;
- Vulnerability remediation; and
- Controlled deployment.
14. Security Certifications
SchoolFlow will not claim certification under standards such as ISO 27001, SOC 2 or PCI DSS unless such certification has actually been obtained and remains valid.
15. Customer Responsibilities
Customers are responsible for:
- Protecting their login credentials;
- Configuring appropriate user permissions;
- Removing inactive users;
- Maintaining secure devices;
- Avoiding password sharing; and
- Reporting suspected security incidents.
16. Security Contact
Security concerns should be reported to:
Email: support@schoolflow.ng

Where Learning Meets Management.
A modern school ERP designed to simplify school operations, improve visibility, and help educational institutions make better decisions.
Resources
Quick Link
© 2026 SchoolFlow ERP | All rights reserved | Powered by Rushdah Innovative Resources
