Access control first — certifications when they’re real
Education data deserves careful handling. LMS Portal leads with role-based access and department scoping, and we only publish compliance claims we can stand behind.
How we protect institutional data today
Practical security controls in the private beta — without overstating formal certifications.
Role-based access control
Four roles — Institution Admin, HOD, Teacher, Student — each with navigation and APIs scoped to what that role can do.
Department-scoped HODs
Department admins only see and change their own faculty. Cross-department visibility is blocked by design.
Secure session login
Email/password authentication with secure session cookies, forced password change on first login, and idle auto-logout.
Least-privilege by default
Teachers stay on assigned classes; students see only their own enrollment, submissions, and published results.
Dedicated institution deploy
Private beta deployments are institution-scoped — not a shared multi-tenant marketplace of unrelated campuses.
Honest about certifications
We do not claim SOC 2, FERPA, GDPR, or WCAG certification until those programs are complete. Ask us what is in place today.
You own your institution's data
Clear ownership and scoped access matter more than badge walls — especially in private beta.
- Your institution owns its data in the deployment database
- Bulk CSV provisioning for users — controlled by Institution Admin
- Login session auditing for sign-in and sign-out events
- Accessibility improvements ongoing — no formal WCAG claim yet
- Sub-processor list available on request once hosting is finalized
- Backup strategy included as part of production deployment
Need a security questionnaire completed?
Our team is happy to walk through your institution's security review as part of an evaluation — with honest answers on what is shipped today.