1. Core Principles of Educational Data Governance
Every byte of institutional and personal data processed across SchoolFees.NG is governed by six fundamental principles:
2. Technical & Cryptographic Architecture
SchoolFees.NG utilizes modern edge-native security architectures to prevent breaches, snooping, or data corruption:
- End-to-End Transport Security (TLS 1.3):All web communication, mobile requests, desktop cloud synchronization, and webhook callbacks are forced over encrypted HTTPS using modern TLS 1.3 cryptographic suites with HSTS enforcement.
- Database Encryption at Rest (AES-256):All relational records, student rosters, parent contacts, and fee balances stored on Cloudflare D1 distributed databases and local Windows desktop SQLite caches are encrypted at rest using AES-256 cipher blocks.
- Secure Password Hashing (PBKDF2 / SHA-256):Staff and parent passwords are salted and hashed with 100,000 PBKDF2 iterations using Web Crypto primitives. Constant-time signature verification prevents timing side-channel attacks.
3. Role-Based Access Control (RBAC) & Least Privilege
Every user inside the school workspace is confined to strict, cryptographically enforced role boundaries:
4. Tamper-Evident Audit Trails & AI Fraud Engine
Continuous Integrity Monitoring:
All critical bursary operations (including invoice creation, manual discount concessions, fee item deletion, cashier session closures, and receipt voiding) automatically append an immutable record to the institutional Audit Trail.
Our embedded 24/7 AI Fraud & Shadow Void Auditor continuously scans transaction graphs to detect anomalous cashier overrides, duplicate admission numbers, or suspicious out-of-hours cash collections, generating real-time security alerts for the school proprietor.
5. Disaster Recovery & Offline Continuity
Recognizing that Nigerian schools frequently operate in environments with intermittent power or fiber connectivity:
- Decentralized Local Vault: The Windows Desktop application operates from an encrypted local SQLite database, allowing bursary cashiers to collect fees and print POS receipts during complete internet blackouts.
- Automated Cloud Replication: When internet connection is restored, the offline engine executes two-way differential synchronization to merge verified receipts into the cloud database without data collisions.
- Geographically Redundant Snapshots: Cloud databases undergo automated daily cryptographic snapshots archived across distributed data centers with 99.999999999% (11 9s) durability.
6. Incident Response & 72-Hour Breach Notification SLA
In compliance with Section 40 of the Nigeria Data Protection Act 2023:
Statutory Notification Protocol:
In the unlikely event of a confirmed security incident involving unauthorized exposure or tampering of personal data, SchoolFees.NG will notify the affected School Data Controllers and the Nigeria Data Protection Commission (NDPC) within seventy-two (72) hours of verification.
The incident notification will detail the nature of the event, categories of data affected, containment measures taken, and recommended institutional remedial steps.
7. Security Audits & DPO Inquiries
For institutional security assessments, vulnerability disclosures, or Data Protection compliance audits:
Security Operations & Data Protection Desk
Email: security@schoolfees.ng / dpo@schoolfees.ng
Emergency Security Hotline: Available inside verified School Owner dashboards.
Have Questions Regarding Our Legal Terms?
Our dedicated Data Protection and Legal Compliance desk is available to assist school owners, legal counsel, and educational boards.