School-wise data isolation
Operational records are school-scoped so one school workspace does not intentionally share its working data with another school workspace.
School Master combines school-scoped data, verified login, tracked sessions, permissions, audit history and protected backup/restore without claiming unsupported certifications.
Operational records are school-scoped so one school workspace does not intentionally share its working data with another school workspace.
Users can be restricted by role and module; supported actions can have separate permissions.
Teacher access can be limited to assigned classes/divisions instead of exposing every class.
Google OAuth and Email OTP login are available with Turnstile/rate-limit protection. Authenticated browser sessions are tracked and restored only while their server-side session remains active.
Sensitive changes can be written to the audit workflow for accountability and review.
The public Live Demo uses a separate read-only fictional workspace rather than exposing customer or QA school data.
School-scoped logical backup export is available and excludes passwords, database credentials and browser-session secrets.
Restore requires recent OTP identity confirmation, validates the backup/school, shows record counts and warnings, creates a pre-restore checkpoint and applies operational changes transactionally.
Active browser sessions are tracked with recent-device history, inactivity protection and controls to sign out other or all sessions.
Backup/Restore, User Management and Academic/Financial Year workflows can require a recent 6-digit Email OTP before sensitive actions continue.
ASP.NET Core Data Protection keys are persisted in Neon PostgreSQL and the stored key XML is encrypted before storage, helping protected browser/session data survive deployments.
The ERP contains sync foundations, but full production-grade offline operation remains a separate roadmap rollout.