Security

Security Overview

A consolidated summary of how Edminhub is designed, operated, and governed to protect school, learner, and staff information.

Owner
Simple Software Development LLC
Product
Edminhub
Version
1.0
Effective Date
29 April 2026
Item Details
Product Edminhub
Owner and Operator Simple Software Development LLC
Purpose School management platform for learner records, attendance, subjects, classes, academic information, disciplinary processes, communication, and related school administration.
Primary Security Objective Protect the confidentiality, integrity, and availability of school, learner, parent, guardian, teacher, and staff information processed through Edminhub.
Contact info@simplesoftwaredevelopment.com | www.simplesoftwaredevelopment.com

1. Purpose of this Security Overview

This Security Overview summarises the technical and organisational measures used by Simple Software Development LLC to protect information processed through the Edminhub platform. It is intended to support school procurement reviews, due diligence checks, internal governance discussions, and parent or stakeholder confidence.

This document should be read together with the Edminhub Security and Privacy Statement, the Edminhub SaaS Subscription Agreement, the Edminhub Data Processing Agreement, and the Edminhub Child Data Protection Statement, where applicable.

This overview does not create a separate warranty, service level, certification, or unlimited security guarantee. The legal rights and obligations of the parties are governed by the applicable written agreement between the school and Simple Software Development LLC.

2. Security Governance Approach

Simple Software Development LLC takes a practical, risk-based approach to Edminhub security. Security controls are designed to be proportionate to the nature of the platform, the sensitivity of learner information, and the operational needs of schools.

Edminhub is developed and operated using practices aligned with recognised information security principles, including control concepts commonly associated with ISO/IEC 27001 and secure application development guidance such as the OWASP Application Security Verification Standard.

Unless expressly stated in writing, Edminhub should not be interpreted as certified under ISO/IEC 27001, ISO 9001, SOC 2, Cyber Essentials, GDPR, POPIA, or any other formal certification or regulatory approval scheme.

Security principle How Edminhub applies it
Least privilege Users and administrators should only receive access required for their role and responsibilities.
Need-to-know access Learner and school information should be visible only to authorised users.
Accountability Important activities may be recorded in audit logs to support investigation and oversight.
Defence in depth Security is addressed through access control, application design, infrastructure controls, backups, monitoring, and user responsibility.
Shared responsibility Simple Software Development LLC secures the platform environment, while schools remain responsible for lawful use, user access decisions, internal devices, and school-level governance.

3. Data Processed by Edminhub

Edminhub may process information relating to schools, learners, parents or guardians, teachers, administrators, and other authorised users. The specific information processed depends on how each school configures and uses the platform.

Edminhub should only be used for legitimate school administration, educational management, communication, safeguarding, compliance, and related operational purposes.

Data category Examples
Learner information Names, learner numbers, grades, classes, subjects, attendance, academic records, disciplinary records, uploaded documents.
Parent or guardian information Names, contact details, relationship to learner, communication details.
Teacher and staff information Names, roles, subjects, classes, contact information, platform access details.
School information School name, grade structure, classes, subjects, administrative configuration.
System information User accounts, roles, permissions, login activity, audit logs, support information, error logs.

4. Access Control and User Permissions

Edminhub uses role-based access control to limit access to information and functions based on user responsibilities. Typical roles may include school administrator, principal, teacher, parent or guardian, learner, and system administrator.

The school is responsible for assigning roles correctly, reviewing access periodically, and removing or updating access when users leave the school or change responsibilities. Simple Software Development LLC is not responsible for unauthorised access caused by incorrect role assignment, shared accounts, weak internal controls, insecure devices, or failure by the school to remove access.

Role type Typical access purpose
School administrator Configure school setup, manage users, permissions, learners, classes, subjects, and reports.
Principal or senior staff View school-level academic, attendance, disciplinary, and operational information.
Teacher Manage assigned classes, subjects, attendance, marks, and learner-related records where authorised.
Parent or guardian Access learner information for their own child or children, where enabled by the school.
Learner Access their own school-related information, where enabled by the school.
Edminhub support Limited access where required for support, security, maintenance, or troubleshooting.

5. Authentication and Account Security

Edminhub applies authentication controls to reduce the risk of unauthorised access. Users are responsible for keeping credentials confidential and must not share accounts or passwords.

Administrative access is intended to be restricted to authorised users only. Where additional security features such as multi-factor authentication are made available, schools are encouraged to enable them for administrative and high-risk accounts.

Control Purpose
Password-based authentication Verifies user identity before granting access.
Strong password practices Reduces the risk of weak or easily guessed credentials.
Session management Reduces risk from unattended or stale sessions.
Restricted administrator access Limits high-impact functions to authorised users.
Optional or future MFA support Adds stronger protection for sensitive accounts where available.

6. Data Transmission and Storage Protection

Edminhub is designed to use encrypted connections where supported to help protect information transmitted between users and the platform. Access to databases, storage systems, and administrative interfaces is intended to be restricted to authorised technical or support personnel where required for service delivery, maintenance, security, or support.

No system can be guaranteed to be completely immune from all cyber threats. Simple Software Development LLC applies reasonable technical and organisational safeguards intended to protect the confidentiality, integrity, and availability of customer data.

7. Backups and Recovery

Backups are performed daily and retained for a period of 7 days.

Point-in-time backups may be available where a school makes a special arrangement with Edminhub / Simple Software Development LLC.

Backups are intended for disaster recovery and operational resilience. They are not a substitute for the school's own recordkeeping obligations, statutory retention requirements, independent exports, or internal data governance processes.

8. Audit Logs and Monitoring

Edminhub may record system and user activity to support accountability, troubleshooting, security monitoring, and investigation of suspected misuse. Audit logs may include login activity, changes to key records, administrative actions, permission changes, and other significant system events.

Access to audit logs is restricted to authorised personnel. Audit logs are operational and security records and may not capture every possible user action or contextual school decision.

9. Secure Development Practices

Simple Software Development LLC aims to develop Edminhub using secure software development practices appropriate for the maturity and risk profile of the platform. These practices are improved over time as the product evolves and operational requirements mature.

Practice Security purpose
Code review Helps reduce defects, insecure logic, and accidental exposure of sensitive data.
Controlled deployment Reduces the risk of unapproved or untested changes reaching production.
Environment separation Reduces risk by separating development and production environments where practical.
Dependency review Helps identify and remediate vulnerable software libraries.
Input validation Reduces injection and data manipulation risks.
Access testing Helps verify that users cannot access information outside their authorised role.
Error handling Reduces leakage of sensitive system or technical information.

10. Vulnerability Management and Security Testing

Simple Software Development LLC may perform internal security reviews, vulnerability checks, application testing, and remediation activities to identify and address weaknesses. Where commercially appropriate, independent security professionals may be engaged to perform vulnerability assessments or penetration testing.

Security testing results may be shared with client schools in summary form where appropriate and subject to confidentiality restrictions. Detailed test outputs, infrastructure information, exploit details, credentials, and sensitive security information may be withheld to protect the platform and other customers.

11. Privacy and Responsible Data Use

Simple Software Development LLC uses personal information processed through Edminhub only for legitimate purposes related to the delivery, support, maintenance, security, administration, and improvement of the platform.

We do not sell school data, learner data, parent data, or teacher data to third parties.

We do not use learner information for advertising purposes.

Edminhub may send school-related communications, service messages, account notifications, administrative messages, and platform-related communications where enabled or required for service delivery.

12. Third-Party Service Providers

Simple Software Development LLC may use reputable third-party service providers to host, operate, secure, monitor, back up, support, or improve Edminhub. These may include hosting providers, infrastructure providers, email delivery services, backup providers, monitoring tools, support tools, analytics tools, and security services.

Where such providers are used, access to customer data is intended to be limited to what is reasonably necessary for the relevant service. Third-party providers are not permitted to use school or learner information for their own unrelated purposes.

Simple Software Development LLC is not responsible for third-party systems, integrations, devices, networks, or services separately selected, connected, or used by the school outside the Edminhub platform.

13. Hosting and Data Location

Edminhub may be hosted using reputable cloud infrastructure providers. Depending on the hosting environment, customer data may be processed or stored outside the country where the school is located.

By using Edminhub, the school acknowledges that cross-border processing may occur where necessary to provide, support, secure, back up, or maintain the service. The school remains responsible for determining whether its use of Edminhub, including any cross-border transfer of personal information, is permitted under laws applicable to the school.

14. Security Incident Response

Simple Software Development LLC maintains procedures for responding to suspected or confirmed security incidents. In the event of a confirmed security incident affecting customer data, Simple Software Development LLC will take reasonable steps to investigate the incident, contain and mitigate its impact, restore affected services where technically possible, and notify the affected school where appropriate.

Notification timelines may depend on the nature of the incident, applicable legal requirements, the information available at the time, and the need to avoid compromising security investigations.

Simple Software Development LLC does not accept liability for incidents caused by the school's own systems, user devices, shared passwords, incorrect permissions, unauthorised internal users, third-party integrations selected by the school, or misuse of the platform by the school or its users.

15. School Security Responsibilities

Security is a shared responsibility. Simple Software Development LLC is responsible for applying reasonable safeguards to the Edminhub platform environment. The school is responsible for the way it configures, administers, and uses Edminhub.

School responsibility Description
User access management Create, update, review, and remove user accounts appropriately.
Role assignment Ensure users only receive access needed for their duties.
Password protection Prevent shared accounts, weak passwords, and credential misuse.
Device security Ensure users access Edminhub from reasonably secure devices and networks.
Lawful use Ensure learner, parent, guardian, teacher, and staff information is collected and used lawfully.
Data accuracy Ensure records entered into Edminhub are accurate and kept up to date.
Parent or guardian access Decide who may lawfully access learner information.
Record retention Decide how long school and learner records must be retained under school policy or applicable law.
Internal training Ensure staff understand how to use Edminhub responsibly and securely.

16. Data Retention, Export, and Deletion

School data is retained for as long as necessary to provide the Edminhub service, comply with legal obligations, support operational requirements, resolve disputes, enforce agreements, maintain audit records, or meet contractual commitments.

Upon termination or expiry of the school's subscription, the school may request export of available customer data within a reasonable period. After termination, Simple Software Development LLC may retain customer data for a limited period for backup, legal, audit, billing, security, or operational purposes, after which it may delete or anonymise the data in accordance with its retention practices, unless otherwise agreed in writing.

Deleted data may remain in backups for a limited period until those backups expire or are overwritten.

17. Security Limitations

Edminhub is designed and operated with reasonable security measures, but no online service can be guaranteed to be completely secure, uninterrupted, error-free, or immune from all cyber threats.

To the fullest extent permitted by applicable law, this Security Overview does not expand the liability of Simple Software Development LLC, its directors, officers, members, employees, agents, contractors, or affiliates beyond the limits agreed in the applicable written agreement with the school.

18. Documents Supporting Security Governance

The following documents may support school due diligence and governance reviews: the Edminhub Security and Privacy Statement, the Edminhub SaaS Subscription Agreement, the Edminhub Data Processing Agreement, the Edminhub Child Data Protection Statement, this Security Overview, and any applicable service plan or order form.

If there is a conflict between this Security Overview and a signed agreement, the signed agreement will take precedence unless the parties expressly agree otherwise in writing.

19. Contact

Questions about Edminhub security, privacy, or data protection may be directed to Simple Software Development LLC.

Contact item Details
Company Simple Software Development LLC
Product Edminhub
Email info@simplesoftwaredevelopment.com
Website www.simplesoftwaredevelopment.com
Address 131 Continental Dr, Suite 305, Newark, Delaware