Updated 11 October 2026

Security · Skoolway

This page describes the controls in the product. It is not a certification, and Skoolway does not claim a SOC report or an independent audit it has not had.

School boundaries

Records are stored against one school. Signing in does not grant a view of another school. A suspended school cannot keep using its portals. Department staff are limited to the workspace they were given.

The parent and learner portal shows the selected learner. It is not a search across the school.

Sign-in

Staff sessions use an HTTP-only cookie. Google sign-in, when someone chooses it, confirms the email with Google. The Google password is never sent to Skoolway. Learner sign-in is a separate page and uses the school code plus the learner identifier.

Payments and private notes

A school’s payment keys stay on the API. They are not sent back to the browser to be displayed in full, and they are not placed in the public pages. Health notes, fee balances, and live vehicle locations are inside the school roles and the learner portal.

Skoolway does not sell learner or school information. Hosting, the database, and Google sign-in are the processors required to run the service. The privacy policy is the longer explanation.