Tenant-aware access
School-owned operations use the authenticated school context. Client-supplied school identifiers do not grant access.
Security
Security is designed into tenant access, permissions, financial transitions and operational audit trails—not left to frontend visibility rules.
School-owned operations use the authenticated school context. Client-supplied school identifiers do not grant access.
SuperAdmin, School Admin, Teacher, Student and Parent workflows are protected by server-authoritative authorization.
Refresh sessions, revocation, password recovery controls and protected routes reduce unauthorized access risk.
Amounts are calculated by the server and online money is credited only after signed gateway confirmation.
Sensitive operational changes and financial transitions produce actor-aware audit records where implemented.
Production activation requires configured monitoring, backup execution and restore testing; provider and rollout evidence must be completed before launch.
A record identifier alone is not treated as proof of school ownership. Tenant-owned reads and mutations require the current school context.
Classes, sections, students, employees and finance references are validated within the same school before protected operations.
Frontend role visibility improves usability, but the API remains the authority for every protected action.
VidyaLynq does not claim certifications that have not been independently completed. Security statements describe implemented controls or explicit launch gates.