Security Overview
Built with security, privacy and modern identity in mind.
Protecting student information and payment data is a foundational part of the SchoolBanks platform. Following a comprehensive review of our student data, payments, and identity systems, we strengthened key areas and confirmed several core protections already operating as designed.
Access control
Role-based access control is aligned to district and school roles with least privilege and tenant scoping.
Authentication
Modern identity platform with SSO support for districts that require stronger identity controls.
Protection and monitoring
SchoolBanks describes TLS in transit, platform-based encryption at rest, restricted logs, and operational monitoring.
Secure development
The DPA references controlled deployment, peer review where feasible, patching, and environment separation.
FERPA-Aligned Data Protection
Student privacy and FERPA-aligned data protection.
We enhanced our data protection practices by eliminating the storage of student personally identifiable information (PII) from operational system logs. Student names and other sensitive search-related information are no longer written to retained application logs, further reducing exposure while preserving the user experience for authorized staff.
The review also confirmed that existing access controls are working as intended. Users only see information they are authorized to access based on their role, organization, and assigned visibility permissions.
PCI-DSS Aligned Payments
Secure payments by design.
SchoolBanks uses modern payment security practices that keep sensitive payment card information out of the application entirely.
Secure, tokenized payment processing through Stripe
No storage or handling of raw credit card numbers or CVV data within SchoolBanks
Encrypted HTTPS communications throughout the payment experience
Secure webhook validation to ensure payment events originate from trusted sources
Enterprise-grade secret management for payment credentials
As part of the review, all payment-related configuration was validated and an outdated development credential was removed and replaced with centralized secret management.
SSO Readiness
Enterprise-ready single sign-on and identity security.
Our authentication and identity platform is built on a modern SSO architecture designed to support secure enterprise and district deployments, with session handling and identity safeguards reviewed on an ongoing basis.
Security controls that keep district identity safe
- Secure session handling, including logout procedures that fully terminate user sessions and settings aligned with modern browser standards
- Secure state and nonce validation to protect against replay and forgery attacks
- Comprehensive identity token verification
- Tenant isolation protections across our multi-tenant SSO architecture
- Support for organization-specific MFA requirements
- Controlled just-in-time user provisioning
Continuous improvement
Security and privacy are ongoing commitments. Our review identified one future enhancement opportunity related to further reducing the amount of student information returned in certain administrative list views. This item is being evaluated to ensure the best balance between usability, performance, and data minimization.
The Bottom Line
The audit confirmed that SchoolBanks maintains strong safeguards around student privacy, payment security, and identity management. Recent enhancements further strengthen our security posture while supporting the seamless experience schools, business offices, and families expect.