INFORMATION SECURITY POLICY

Effective Date: 1/8/2026
Last Updated: 5/9/2026

1. Purpose

SchoolFlow recognises the importance of protecting customer, school, student, teacher and financial information.

This Information Security Policy establishes the general security principles used to protect SchoolFlow systems and information.

2. Security Principles

SchoolFlow seeks to maintain:

  • Confidentiality;
  • Integrity;
  • Availability;
  • Accountability; and
  • Resilience of information and systems.

3. Access Control

Access to SchoolFlow systems should be restricted according to business need and user responsibilities.

Security controls may include:

  • User authentication;
  • Role-based access;
  • Least-privilege principles;
  • Administrative access restrictions;
  • Account management; and
  • Access revocation.

4. Password Security

SchoolFlow should maintain appropriate controls relating to:

  • Password complexity;
  • Password protection;
  • Authentication;
  • Account lockout or rate limiting where appropriate; and
  • Credential security.

5. Encryption

Where technically implemented, sensitive information should be protected using appropriate encryption:

  • During transmission; and
  • At rest where appropriate.

Specific encryption standards should be documented internally based on the actual infrastructure.

6. Infrastructure Security

SchoolFlow infrastructure should be protected using appropriate measures such as:

  • Firewalls;
  • Network controls;
  • Access restrictions;
  • Security monitoring;
  • System hardening;
  • Vulnerability management; and
  • Secure configuration practices.

7. Data Segregation

Where SchoolFlow operates as a multi-tenant SaaS platform, reasonable technical and organisational controls should be implemented to prevent unauthorised access between customer environments.

8. Logging and Monitoring

SchoolFlow may maintain logs relating to:

  • Authentication;
  • Administrative actions;
  • Security events;
  • System activity;
  • Errors; and
  • Other events necessary for security and operational purposes.

9. Backups

SchoolFlow should maintain appropriate backup mechanisms designed to support recovery from:

  • Hardware failure;
  • Software failure;
  • Accidental deletion;
  • Cybersecurity incidents; and
  • Other operational disruptions.

10. Vulnerability Management

SchoolFlow should take reasonable steps to identify and address security vulnerabilities within its infrastructure and application.

11. Incident Response

In the event of a suspected security incident, SchoolFlow may:

  1. Identify and assess the incident;
  2. Contain the incident;
  3. Investigate its scope;
  4. Remediate affected systems;
  5. Restore affected services;
  6. Determine whether notification obligations apply; and
  7. Take preventative measures.

12. Employee and Contractor Security

Personnel with access to SchoolFlow systems should be subject to appropriate confidentiality and security obligations.

Access should be limited according to their responsibilities.

13. Secure Development

Where applicable, SchoolFlow development processes should incorporate:

  • Code review;
  • Secure coding practices;
  • Dependency management;
  • Testing;
  • Vulnerability remediation; and
  • Controlled deployment.

14. Security Certifications

SchoolFlow will not claim certification under standards such as ISO 27001, SOC 2 or PCI DSS unless such certification has actually been obtained and remains valid.

15. Customer Responsibilities

Customers are responsible for:

  • Protecting their login credentials;
  • Configuring appropriate user permissions;
  • Removing inactive users;
  • Maintaining secure devices;
  • Avoiding password sharing; and
  • Reporting suspected security incidents.

16. Security Contact

Security concerns should be reported to:

Email: support@schoolflow.ng

Where Learning Meets Management.

A modern school ERP designed to simplify school operations, improve visibility, and help educational institutions make better decisions.

© 2026 SchoolFlow ERP | All rights reserved | Powered by Rushdah Innovative Resources