Skip to main content
TavechTavech
Security

You are handing us your children's records. That deserves proof.

Not a policy document promising that somebody, somewhere, is careful. The commitments below are things you can check for yourself from inside your own school's Tavech — on your first day and on your ten-thousandth student.

Your records are yours

Your school has its own address, its own accounts and its own records. Nothing your school holds is reachable from anywhere outside it — not by another organisation, not by a mistyped link, not by an old bookmark.

Access you decide

Your bursar sees fees. Your class teacher sees their own register. A parent sees their own children. You set who can do what, and the answer is checked every single time — not merely hidden from the menu.

Parents see only their own children

A guardian signs in and finds their children — attendance, published results, what is owed. Another family’s child is simply not there for them, and no amount of guessing changes that.

Every change is answerable

Marks, fees, permissions, published results, account status — each change records who made it, when, and what it was before. When a parent disputes a grade a year later, you have the answer rather than a memory.

Your rules, not ours

Password strength, how long a session lasts, how many failed attempts lock an account, whether you require a second factor. Your school decides. We do not impose a policy on you and call it best practice.

Hard to attack, quick to recover

Sign-in attempts are throttled, sessions can be revoked one at a time, and your data is backed up continuously with a restore procedure we have actually rehearsed.

In place today

Operational practices

In transit

Everything between your staff and Tavech travels encrypted, always.

Passwords

Stored so that nobody — including us — can read them. They can be reset, never recovered.

Sessions

Sign out and the session ends there and then. You can end any session from any device.

Backups

Taken automatically, with a restore procedure that has been tested rather than assumed.

Availability

Built to stay up, with planned work announced in advance and never during your school day.

Your data on exit

Leave whenever you like and take a full export with you. We do not hold your records hostage.

Certification roadmap

On the roadmap

We name these as work in progress rather than claim them, because a certificate you have not earned is the first thing worth lying about. The controls behind them are already how your school runs. Ask any vendor to show you the certificate itself, us included.

  • Formal SOC 2 Type II audit
  • ISO 27001 certification
  • Third-party penetration testing programme
  • Customer-managed encryption keys
  • Published status page and incident history

Send us your security questionnaire.

We would rather answer your board's hardest questions before you commit than after. Send the document your governors use and we will complete it and return it signed.