Security
Plainly, and without the badges: here is what actually protects your records, and what we ask of you.
Everything between your browser and our servers travels over HTTPS. Nothing about your school crosses the network in the clear.
Your records are stored encrypted on disk by our database provider, so a stolen drive is not a stolen register.
The database itself decides what each person may see. A teacher reaches their own classes, a parent only their own children — enforced by row-level security, not by hiding buttons.
Every record carries the school it belongs to, and every query is filtered by it. Your school's data is never mixed with another school's.
Our database provider takes automated backups, so an accident on a Tuesday afternoon does not cost you the term.
Export your learners, fees and reports whenever you want, and ask us to delete them when you leave. We do not sell anything to anyone.
We are not certified against any security standard, and we would rather say so than imply otherwise. What we do commit to is set out in full in our privacy policy, and it is the substance of the rights the GDPR describes:
Learner information is held so that a school can run: registers, fees, reports. It is not used for advertising, it is not sold, and it is not shared with anyone outside the school except the providers that host it for us.
My School Flow runs on managed cloud infrastructure, and your records sit in a managed Postgres database. Both the application and the database are operated by established providers rather than by machines under our own desks, which is what gives you the encryption, the backups and the patching described above.
Most school data is lost through a shared password, not through a broken server.
Longer beats complicated. A phrase of a few unrelated words is both easier to remember and harder to guess than a short password full of symbols.
Do not reuse your school password anywhere else. If another site is breached, your school should not be breached with it.
Most of what protects you in a browser arrives as an update. Running last year's version gives that up.
Give each member of staff their own account. Shared logins mean nobody can tell who did what, and removing one person means changing everyone's password.
We will never email you asking for your password. If a message asks for it, it is not from us.
If something looks wrong — an unexpected change, a message you did not send — say so straight away. Early is cheap.
Tell us and we will look at it straight away. We would far rather hear it from you than not hear it.