Skip to content
msomi School Management
Security

Schools hold data about children. That sets the bar.

Almost everything a school records concerns a minor, which makes schools among the most heavily obligated data controllers in Kenya. Here is what we do about it, and what remains your responsibility.

Controls

Tenant isolation at the data layer

Every record belongs to a school, and queries are scoped to the signed-in school before they run — not filtered afterwards in the page that displays them. There is no report, search or export that can return another school’s records.

Access follows responsibility

A teacher sees the streams they are allocated to. A class teacher sees their own roll. A guardian sees their own children. A driver sees today’s route and manifest. Very little needs configuring because access is derived from relationships the school already maintains.

Sensitive records restricted further

Medical information, clinic visits and safeguarding records are limited to designated medical and pastoral staff rather than visible to anyone holding an administrative login.

Authentication and session control

Passwords are set by the account holder — never by the school and never by us — after verifying a one-time code. Sessions expire and refresh, and ending or suspending a member of staff revokes their access immediately.

Encryption in transit and at rest

All traffic runs over TLS. Data at rest is encrypted, and backups are encrypted and tested.

Export on demand

Every list exports to Excel whenever you want, without asking us. Data portability is a control, not a courtesy — it is what stops a vendor relationship becoming a hostage situation.

The Data Protection Act 2019

Under the Act, your school is the data controller and Msomi is a data processor. That distinction matters: you decide what is collected and why, and we process it only on your instructions and only to provide the service.

We sign a data processing agreement with every school that sets out:

  • What categories of personal data we process, and for what purposes
  • That we do not sell, share or use school data for our own purposes
  • Our security obligations and breach notification commitments
  • How we assist you in responding to data subject requests
  • What happens to your data when the agreement ends

Principles as they apply in the product

Purpose limitation. Fields exist because a school process needs them. We do not collect learner data speculatively in case a future feature wants it.

Data minimisation. Access is scoped by responsibility. Most staff never see most of the school's data, because their role does not require it.

Accuracy. One authoritative record per person is a data protection property as much as an operational one — a correction made once is a correction made everywhere, rather than one of five copies being fixed.

Storage limitation. Retention follows the school's own policy. Alumni records persist because schools have a legitimate need to reissue transcripts years later; that is a decision the school makes and documents.

Where your data lives

School data is hosted in an African region rather than routed to Europe or North America, which keeps latency low and simplifies your position on cross-border transfers. We can confirm the exact region in writing as part of your data processing agreement.

Reporting a vulnerability

If you believe you have found a security issue, please tell us at hello@msomionline.com before disclosing it publicly. We will acknowledge within two working days, keep you informed while we investigate, and we will not pursue action against anyone who reports in good faith and does not access, modify or retain data belonging to a school.

Due diligence

Need our security documentation?

We can provide our data processing agreement, hosting details and security overview for your board or your legal adviser before you commit to anything.

Or try it first — the Trial tier gives you a full term, free, with every module unlocked.