Security model
Separation is enforced, not assumed.
AcademicFirst handles sensitive student, family, staff, and financial records. The rules below are implemented in the platform's request handling — interface hiding is a convenience on top, never the boundary itself.
Membership-checked requests
A signed-in token alone opens nothing. Each school-scoped request resolves the caller's active membership for that school first — no membership, no data.
Platform stays out of schools
Platform operators can provision and list schools, but holding a platform role grants zero automatic access to any school's students, fees, or files.
Guessing-proof IDs
Asking for a school or record you cannot access returns the same answer as asking for one that does not exist, so IDs cannot be probed.
Authorized files only
Documents and photos stay in private storage. Downloads are short-lived links issued after an authorization check — parents reach only linked students' files.
What we do not claim: third-party certifications, regulatory compliance attestations, encryption-standard guarantees, or uptime promises are not part of the platform's documented offering and are not stated here.
Bring your school's records into one system.
Walk through the proposed onboarding above, then request a demo — every step from there is confirmed with you.