Records, roles, workflows and communications stay in one accountable workspace.
Trust centre · security
Security
Security is a shared responsibility. SchoolSuite365 combines access controls, auditability, operational safeguards and a clear route for reporting vulnerabilities or suspected exposure.
Schools govern their data and permissions; the platform provides the controls and evidence.
Automation can assist operations, but authorised people remain responsible for outcomes.
Security programme
MBTS NIG. LTD. operates SchoolSuite365 with a risk-based security programme covering identity, tenant boundaries, secure development, infrastructure, backups, monitoring, incident response and resilience. Controls evolve as the platform, threats and school requirements change. Current contractual security commitments and applicable law govern where they provide more specific requirements.
Access and tenant protection
- Role-based permissions, school scoping and least-privilege workflows help limit access to the records a user needs.
- Authentication safeguards include secure sessions, throttling, account protections, audit events and controlled recovery workflows.
- Administrators should review roles regularly, remove leavers promptly, use strong unique passwords and protect devices and recovery methods.
- Never share an account or use another person’s session to work around a permission restriction.
Data protection in operation
- Sensitive records are handled through authenticated application routes rather than public file paths wherever the feature supports it.
- Upload validation, CSRF protection, output escaping and server-side permission checks reduce common web and workflow risks.
- Audit trails and operational logs support investigation of important administrative, payment, approval, access and security events.
- Connected payment, messaging, email, push and hosting providers are enabled by the school and may have separate controls and terms.
Infrastructure, backup and resilience
The school and platform operator maintain layered availability measures appropriate to the deployment, including database safeguards, operational monitoring, controlled backups and restoration procedures. Backups are not a substitute for access control: they must remain private, encrypted or access-restricted, tested for restoration and handled according to the school’s retention schedule.
Monitoring and incident response
Security and reliability signals may be logged, reviewed and alerted on to identify abuse, failed jobs, unusual access, integration failures and service degradation. When an incident is confirmed, the response focuses on containment, evidence preservation, risk assessment, remediation and clear communication to affected schools and authorities where required.
Responsible disclosure
- Report privately through the school’s authorised security or support route and mark the subject “Confidential security report”. Include the affected URL or app release, impact, reproducible steps, a minimal proof of concept and a safe follow-up method.
- Use test accounts and test records only. Stop testing when you confirm a vulnerability and share the smallest evidence needed to reproduce it.
- We aim to acknowledge a credible report, validate scope and impact, apply mitigations and coordinate disclosure where appropriate. Please allow reasonable time before public disclosure.
- If personal, financial, academic, payroll or safeguarding data may have been exposed, alert the school’s designated privacy or safeguarding lead immediately as well as using the security route.
Testing boundaries
- Do not perform denial-of-service, destructive actions, social engineering, credential attacks against real users, spam, physical intrusion or tests that could affect school operations.
- Do not access, copy, alter, download or disclose another person’s data. Do not use a real student, family, staff, payment or payroll record as a proof of concept.
- Do not upload malware or intentionally bypass a control beyond the minimum safe step needed to demonstrate the issue.
Shared responsibility
MBTS NIG. LTD. protects and operates the platform within the agreed service scope. Schools remain responsible for lawful data use, role design, user training, device security, local network controls, connected-provider configuration, backup decisions and timely incident escalation. Security works best when both sides act quickly and document decisions.
Security updates
This page is a platform-level overview, not a promise that any particular control is suitable for every deployment. The effective date and version above identify the current public summary. Material changes may be reflected here and communicated through the school’s operational or contractual channels.
Found a security concern?
Do not publish details or test against real records. Use the private Security reporting route and alert the school’s designated lead.