Security is not an add-on module.
It is our core foundation.
After PowerSchool's breach exposed 62 million student records, school districts deserve full transparency. We publish our architecture, isolation specs, and pen testing results.
Why PowerSchool's breach forced a fundamental shift in K-12 software.
In December 2024, PowerSchool suffered the largest student data breach in American history. The vulnerability was architectural: a shared database schema without strict multi-tenant engine isolation and optional MFA authentication for staff.
POWERSCHOOL ARCHITECTURAL ROOT CAUSES
Flaws ExposedBREACH TIMELINE & REGULATORY IMPACT
National K-12 Security Audit
62 million student records exposed across North America due to shared database architecture.
Multiple Departments of Education and Privacy Commissioners open formal audits.
Federal court documents reveal root cause: optional MFA and unsegregated database schemas.
Districts nationally require published zero-trust architecture before renewing SIS contracts.
Six non-negotiable security layers
Click any security pillar to inspect our technical specification.
Zero-Trust Architecture
PostgreSQL Row-Level Security (RLS)
Database transactions execute set_config('app.tenant_id', tenantId) bound by AsyncLocalStorage. RLS policies force the DB engine itself to reject cross-tenant queries.
Encryption at Rest & In Transit
Mandatory WebAuthn MFA
83,000-Line Granular RBAC Engine
Immutable 7-Year Audit Logs
Live Posture Verification
Zero-Trust Security Controls
Infrastructure & Isolation Specifications
Cloud Infrastructure
Cloudflare Workers
Global Edge · 300+ Cities
Edge Runtime
V8 Isolates
No Shared Container Tenancy
Database
Postgres + Tenant RLS
Row-Level Isolation Per District
Disaster Recovery
Blue / Green Failover
R2 Snapshots · Automated Rollback
Availability SLA
99.9% / 99.99%
Standard / District+ Tier
Incident SLA
< 1 Hour Notice
Mandatory Transparency
