Security

How we protect your academy’s data

A school holds children’s records and fee information, so protecting them is part of the product, not an add-on. Here is what is in place today, in plain language.

Every academy is walled off

One academy cannot read or change another academy’s students, fees or staff. The separation is enforced by rules inside the database itself, not only by what the screens choose to show.

Roles are enforced where the data lives

Each role can only change what its job needs. Teachers work with their own batches’ attendance and marks and cannot see fee records. Accountants handle finance, the front desk handles admissions and parents, and only admins manage staff, classes and settings.

Branches stay separate (Pro)

A branch’s staff only ever see their own branch. A Group Admin can move between branches, and the choice is checked by the database every time, so a forged request gets nothing extra.

Parents see only their own child (Pro)

Through the Parent Portal a guardian can read attendance, fees and exam results for their own children. They cannot change anything, and they cannot reach any staff screen or any other family.

Expired accounts are locked, not deleted

When a trial or paid period ends, the academy becomes read-only at the database level and nobody can change its records. The data is kept, and everything reopens when the account is renewed.

Careful sign-in

Passwords are handled by Supabase Auth and are never stored in readable form, even by us. A failed sign-in never reveals which emails have accounts. Staff accounts are created by your admin with a one-time password shown once, and can be deactivated at any time.

We never hold your money details

Academy+ does not process payments and never stores card or bank details, whether for your subscription or for any fee a school collects from its own students. Subscriptions are paid by bank transfer, outside the product.

Your data, on request

On request we can export all of an academy’s data, or permanently delete the academy and its logins. Both exports and deletions by our team are recorded in an audit log.

Built on established providers

The app is hosted on Vercel and the data and sign-in live with Supabase. Everything travels over encrypted HTTPS connections, and the site refuses to be embedded inside other sites.

We test these protections by attacking them

The rules above are not just written down. We try to break them: one academy reading another’s records, a teacher trying to promote their own login to admin, a parent trying to open a different family’s child, a locked academy trying to save changes. Each of those attempts is kept as an automated test, and we run the whole set again whenever the database changes.

Your part

Security is shared. These three habits cover most of what an academy controls.

Choose strong passwords

Ask staff to change their one-time password after the first sign-in, from the Account page.

Deactivate leavers

When someone leaves, deactivate their login under Users & Permissions. They are signed out on their next request.

Sign out on shared devices

On a phone or computer other people use, sign out when you are done.

Found something that worries you?

No system is perfect. If you think you have found a security problem, email sales@twobitdigital.com with the details and we will look into it promptly.

Read our Privacy Policy and Terms of Service. Last reviewed October 2026.

See it for yourself

Take the guided demo to see how roles and branches keep each person to their own part of the academy, or start a free trial with your own data.