Security & trust
How we protect school rota data and operate a multi-tenant SaaS platform for UK schools and trusts.
SchoolRota is built for UK schools. We treat staff rota data as sensitive operational information and apply sensible defaults for access control, audit logging, and tenant isolation.
Tenant isolation
Each customer organisation is a separate tenant. Staff, rotas, and audit events are scoped by tenant ID at the database and application layer. There is no cross-tenant data access in the shared SaaS deployment.
Multi-site organisations
MATs and federations run multiple sites within one tenant. Operational data (rotas, zones, day instances) is site-scoped; users with site-level access cannot read or publish another school's board unless they hold trust-wide roles. Client-supplied site identifiers are never trusted without server-side resolution under the authenticated tenant.
Authentication
Local email/password with bcrypt hashing. Optional SSO (OIDC) and SCIM provisioning for trusts using Entra ID, Okta, or Google Workspace. Operator and billing APIs require separate credentials and fail closed when not configured.
Hosting
Production targets UK/EU regions with TLS on all public endpoints. Staging runs on Fly.io in the London (lhr) region with encrypted volumes.
Backups & retention
Production databases use automated backups with point-in-time recovery. Schools can export rota data from the Exports area; deletion requests are handled via the school admin and our DPA.
Contact
Security questions: security@schoolrota.com