Security at LumikaHub

School data is sensitive. Here is how we protect it.

How we keep your data safe

Security is built into every layer of LumikaHub — from authentication to database access.

JWT-Based Authentication

Every session is protected by a signed JSON Web Token (JWT). Tokens are issued at login, expire automatically, and are verified server-side on every authenticated request — no session state is stored on the server.

Role-Based Access Control

LumikaHub enforces strict role separation across six roles: Super Admin, School Admin, Bursar, Teacher, Parent, and Student. Each role can only access the data and actions it is explicitly permitted to perform — both in the UI and at the API layer.

Data Isolation per School

Each school's data is fully isolated. A school administrator, bursar, or teacher at one school cannot query, view, or modify records belonging to any other school. All database queries are scoped by school ID.

Encrypted in Transit

All traffic between your browser and LumikaHub is encrypted using HTTPS/TLS. Sensitive data — including login credentials and financial records — is never transmitted in plain text.

Input Validation & Sanitisation

Every API endpoint validates incoming data using Zod schemas before processing it. Malformed, missing, or out-of-range values are rejected at the boundary — before they can reach the database or business logic.

Regular Security Reviews

Our engineering team conducts ongoing dependency audits, code reviews, and vulnerability assessments. We stay current with security patches for all third-party libraries used in the platform.

Common questions

Where is school data stored?

All data is stored in a managed PostgreSQL database hosted within a secure cloud environment. Data is backed up regularly and access is restricted to authorised LumikaHub systems only.

Can one school see another school's data?

No. Every database query is scoped to the authenticated school's ID. There is no pathway — in the API or the UI — for one school's users to access another school's records.

How are passwords stored?

Passwords are hashed using a strong one-way algorithm before being stored. Plain-text passwords are never written to the database or to any log.

What happens if a user's token is stolen?

JWTs have a short expiry window. When a token expires the user must log in again to obtain a new one. We recommend schools enforce a strong password policy to minimise the risk of credential compromise.

How do I report a security concern?

Please email hello@lumikahub.com with a description of the concern. We aim to acknowledge all security reports within 24 hours.

Have a security question?

Email us at hello@lumikahub.com and we'll respond within 24 hours.