Security at LumikaHub
School data is sensitive. Here is how we protect it.
How we keep your data safe
Security is built into every layer of LumikaHub — from authentication to database access.
JWT-Based Authentication
Every session is protected by a signed JSON Web Token (JWT). Tokens are issued at login, expire automatically, and are verified server-side on every authenticated request — no session state is stored on the server.
Role-Based Access Control
LumikaHub enforces strict role separation across six roles: Super Admin, School Admin, Bursar, Teacher, Parent, and Student. Each role can only access the data and actions it is explicitly permitted to perform — both in the UI and at the API layer.
Data Isolation per School
Each school's data is fully isolated. A school administrator, bursar, or teacher at one school cannot query, view, or modify records belonging to any other school. All database queries are scoped by school ID.
Encrypted in Transit
All traffic between your browser and LumikaHub is encrypted using HTTPS/TLS. Sensitive data — including login credentials and financial records — is never transmitted in plain text.
Input Validation & Sanitisation
Every API endpoint validates incoming data using Zod schemas before processing it. Malformed, missing, or out-of-range values are rejected at the boundary — before they can reach the database or business logic.
Regular Security Reviews
Our engineering team conducts ongoing dependency audits, code reviews, and vulnerability assessments. We stay current with security patches for all third-party libraries used in the platform.
Common questions
Where is school data stored?
All data is stored in a managed PostgreSQL database hosted within a secure cloud environment. Data is backed up regularly and access is restricted to authorised LumikaHub systems only.
Can one school see another school's data?
No. Every database query is scoped to the authenticated school's ID. There is no pathway — in the API or the UI — for one school's users to access another school's records.
How are passwords stored?
Passwords are hashed using a strong one-way algorithm before being stored. Plain-text passwords are never written to the database or to any log.
What happens if a user's token is stolen?
JWTs have a short expiry window. When a token expires the user must log in again to obtain a new one. We recommend schools enforce a strong password policy to minimise the risk of credential compromise.
How do I report a security concern?
Please email hello@lumikahub.com with a description of the concern. We aim to acknowledge all security reports within 24 hours.
