Security and Data Protection
Security and Data Protection
Edited in March 2026
1. Security priorities
The security of data belonging to students, teachers, and educational establishments is a core priority for Scolaro. This page summarizes the main technical and organizational safeguards we apply.
For the personal information protection framework, also consult the Law 25 page.
Security is an ongoing process. We evolve our practices based on emerging risks, product needs, and recognized best practices.
2. Infrastructure and access
Hosting and encryption
- Scolaro relies on established cloud infrastructure to host its services.
- Communications use encryption in transit, and stored data benefits from encryption-at-rest mechanisms.
- Backups and redundancy mechanisms support service availability.
Authentication and access control
- User authentication relies on secure session and password management mechanisms.
- Access to data is role-based and restricted to the permissions required.
- Students, teachers, and administrators only see the data within their authorized scope.
Logging and traceability
- Technical logs help trace certain sensitive actions and support auditing.
- Role changes and certain privileged actions may be controlled and logged.
- Logs help detect anomalies and support investigations when a problem occurs.
3. Application security
Secure development practices
- The codebase follows input validation practices and aims to reduce exposure to common vulnerabilities.
- Critical dependencies should be maintained and reviewed regularly.
- Code review and technical verification contribute to risk reduction.
Sessions, tokens, and abuse prevention
- User sessions are managed with time-limited tokens.
- Mechanisms can invalidate sessions at logout or after inactivity.
- Measures such as rate limiting and application controls help prevent abuse and some classes of attack.
4. Data protection
Minimization, integrity, and availability
- We collect only the data required for the pedagogical operation of the platform.
- Data is retained for a reasonable period based on its use and applicable obligations.
- Backup and restoration mechanisms support data integrity and availability.
Transfers to third-party providers
- When some features rely on third-party providers, contractual and technical safeguards are sought.
- Transfers are limited to what is strictly necessary and must align with the applicable framework, including Law 25.
- Data is minimized or anonymized where possible before transfer.
5. Monitoring and incident response
Detection and monitoring
- Monitoring tools help detect anomalies, suspicious behavior, and certain technical incidents.
- Alerts may be triggered to enable a timely response.
Incident management
- Scolaro maintains an incident response framework to analyze, contain, and correct security issues.
- When required, affected people or institutions may be informed in line with applicable legal obligations.
- Corrective measures are intended to reduce immediate impact and prevent recurrence.
6. Shared responsibilities and reporting
Shared responsibilities
- Scolaro must maintain a level of security appropriate to the platform and its data.
- Users must protect their credentials, use strong passwords, and report suspicious activity.
- Educational establishments must manage access and apply their own internal policies.
How to report an issue
If you suspect a security issue or discover a vulnerability, use the contact form and clearly indicate that it is a security report.
- Do not attempt to exploit the vulnerability beyond what is necessary to demonstrate it.
- Do not access data that does not belong to you.
- Do not modify or delete data.