Security & Compliance

Your School Data is Protected

eBingwa uses secure login controls, role-based permissions, and backup processes to help schools protect student, guardian, and finance records. We describe only the safeguards we can support publicly and review them as the product changes.

Role-based
School access controls
Secure login
Protected user access
Backups
Operational recovery process
Audit trail
Key actions logged

Data Protection

We take school data protection seriously. Your records are encrypted, isolated on secure servers, and never shared with third parties.

Encryption in Transit & at Rest

Data sent between user devices and eBingwa is protected during transit, and stored records are protected within the platform environment. We avoid marketing shorthand and focus on practical safeguards schools care about.

  • Protected web sessions for staff, guardians, and admins
  • Secure handling of core student and finance records
  • Authenticated API access for supported workflows
  • Ongoing platform maintenance and patching

Automated Backups

eBingwa includes backup processes as part of day-to-day platform operations so schools can recover from common mistakes and service issues more safely than paper-only workflows.

  • Automated backup routines
  • Recovery planning as part of operations
  • Safer than single-copy paper records and laptops
  • Additional details shared during onboarding where relevant

Role-Based Access Control

Control exactly who can see and modify what information. Assign roles (Principal, Bursar, Teacher, Guardian) with granular permissions. Every action is logged in an audit trail.

  • Granular administrative permission system
  • Pre-defined roles (Principal, Bursar, Teacher, Parent)
  • Custom role creation and profile locking
  • Complete audit trail of all core system adjustments

Password Policies

Strong password requirements and optional two-factor authentication (2FA) keep accounts secure. Passwords are hashed using bcrypt and never stored in plain text.

  • Minimum complexity requirements enforced
  • Bcrypt password hashing protects login codes
  • Secure session timeout on inactive tabs
  • Fast password reset via verified emails

Privacy & Data Handling

We design eBingwa around Kenyan school privacy expectations and data-handling responsibilities, and we describe only the controls we can support publicly.

Data Ownership

You own your data. You can export all your school's information at any time in standard formats (CSV, Excel, PDF). Built with Kenyan school operational workflows and privacy expectations in mind, ensuring administrative peace of mind.

Privacy First & ODPC Alignment

We design product decisions around Kenyan school privacy expectations, limited support access, and clear school ownership of data. eBingwa staff only access records when support is requested and the situation requires it.

Security Frequently Asked Questions

Find answers to common questions about how we protect your school's information.

Who owns the data uploaded to EBingwa?

Your school owns its data. You can export records from the platform, and if you decide to leave, you can request data deletion through the support process.

How often is school data backed up?

Backups are part of our operational process. If your school needs more detail on recovery expectations for a rollout or review, ask during onboarding or support.

Is our data encrypted?

Yes. We use standard transport and storage safeguards to help protect data handled by the platform.

Can EBingwa staff see our student records?

Access is strictly limited. Our support team can only view your data if you explicitly grant permission during a support request. All such access is logged and reviewed.

Is EBingwa compliant with Kenya's Data Protection Act?

eBingwa is designed around Kenyan school privacy expectations and data-handling responsibilities. If your school needs a formal legal or compliance review, confirm the latest position directly with the founders before procurement.

What happens if a teacher loses their phone?

Administrators can instantly revoke access for any user account from the school dashboard. Since data is stored in the cloud and not on the device, the records remain secure.

How do you prevent unauthorized login attempts?

We use rate limiting, account lockout policies, and notify administrators of suspicious login activity. We also support two-factor authentication (2FA) for sensitive accounts.

Can we recover deleted records?

The system includes a "soft-delete" feature for many records, allowing administrators to restore accidentally deleted data within a certain timeframe before permanent removal.

Have Security Questions?

We're transparent about our security practices. If you have specific questions about data protection, backups, or compliance, we're happy to discuss them.