Security & privacy

School data protected by design, not by policy alone

Azhni handles children's data, so isolation and access control are enforced at the data layer and reviewed as part of every release.

How it works

Our security foundations

Tenant isolation in the database

Every school is its own workspace. Access rules are enforced by database row-level policies, not only by the interface.

Role-based access

Administrators, teachers, parents and students each see only what their role and their assignments allow.

Invitation-only accounts

There is no public sign-up. Accounts are created by Azhni or by the school administrator.

Child-data minimisation

We collect what a school day needs. Sensitive administrative fields are stored separately and restricted to school administration.

Audit logging

Sensitive actions — attendance corrections, record edits, role changes, exports — are recorded with who and when.

No parent-to-parent visibility

Parents see only their own linked children. Other families' data is never exposed to them.

Access model

  • School administrators manage people and records within their own school only.
  • Teachers act within their assigned classes and subjects; class teachers approve what reaches parents.
  • Students sign in with school code, student code and a PIN designed for children.
  • Platform staff access is separated from school data and governed by explicit roles.

What we do not claim

We do not advertise certifications we have not obtained. If your school requires a specific standard, security questionnaire or data-processing agreement, raise it during your demo and we will answer precisely about our current posture and roadmap.

Your data

Export and deletion

A school can request an export of its workspace or deletion of its data. See the privacy and data deletion pages for the current process.

Security questions before a pilot?

Book a demo and bring your IT or data-protection lead — we'll go through the access model in detail.