Security
How TeachFolio protects schools’ data. Ask us for more detail for your IT or procurement team.
Access
- Two-step sign-in with an authenticator app, required for owners and school managers and available to everyone; recovery codes; email alerts for sign-ins from new browsers.
- Passwords checked against known data breaches and stored only as one-way hashes; sign-in attempts rate-limited.
- Each school is separated by its own address and checked on every request; managers are view-only in departments; teachers see only their own work and the department’s exemplars.
- Sessions are encrypted and end after inactivity (12 hours, or 1 hour for the owner console). “Sign out of all other devices” is on every account.
- Support access (“log in as”) needs a fresh authenticator code, shows a banner, is logged, and ends after 30 minutes.
Application
- HTTPS only (HSTS), a strict Content-Security-Policy, and protection against framing, MIME sniffing and referrer leaks.
- Every upload is checked: the content must match the file type; executable and web content is refused; optional virus scanning.
- Files open in a sandbox; only PDFs, images and media display in the browser.
- Dependencies are audited automatically and updated weekly; every change is tested (including on MySQL) before release, and releases can be rolled back in seconds.
Data
- Nightly database backups, copied off the server encrypted, automatically test-restored, kept 30 days.
- An activity log of sign-ins and administrative actions; errors alert the team at once.
- Schools choose how long hand-ins are kept, can export everything, and can have everything deleted.
Reporting a problem
If you find a security issue, email us (address below). Please don’t access other people’s data or disrupt the service; we will reply quickly and credit you if you wish.
Who we are
TeachFolio
Contact: hello@example.com