Skip to content

Security

How KlasPoint protects your centre and your students.

Tutorial centres trust KlasPoint with student records and payments. This page explains, plainly, the protections built into the platform.

Each centre's data is kept separate in the database

KlasPoint serves many tutorial centres from one platform, so separation between them is enforced where the data lives, not only in the application.

  • Row-level security is enabled on the database tables, checking on every request that the signed-in user belongs to the centre whose records they are reading or changing.
  • A bug in a page cannot show one centre another centre's students, because the database itself refuses the query.
  • Privileged database access is limited to specific server-side operations, such as confirming a payment, and is never available to the browser.

People only reach what their role allows

Centre staff work in one of three roles — Owner, Admin and Teacher — each with a defined set of areas.

  • Teachers cannot see fees, revenue, payout details or centre settings.
  • Only an owner can change the payout bank account, the KlasPoint plan, or appoint owners and admins. That rule is enforced by the database, so it holds even against a crafted request.
  • Students see their own records and the content of classes they have access to.

Payments are verified before anything unlocks

Student payments are made through Flutterwave's checkout, so card and bank details are entered with the payment provider rather than on KlasPoint.

  • Incoming payment notifications must carry the expected signature before KlasPoint considers them.
  • KlasPoint then verifies each transaction independently with Flutterwave and checks that the amount matches what was charged.
  • Only then is the payment recorded and the student's access extended.

Accounts are protected

Accounts are protected at sign-up, at sign-in, and when a password is reset or changed.

  • Passwords must be at least 8 characters and include a letter and a number.
  • Password reset links are sent by email and can only be used once.
  • Changing a password while signed in requires the current password first.
  • Centres can restrict each student account to one device at a time, and accounts that keep switching devices are flagged as possible sharing.

The AI assistant only sees what it should

The WhatsApp assistant works with student information, so it is scoped tightly.

  • A student must link and verify their WhatsApp number before the assistant will discuss their account.
  • Answers about fees, attendance and schedules are limited to that student's own records.
  • The business copilot answers only from the centre's own data, and can post announcements but not edit payments or delete records.

Connections are encrypted

The KlasPoint website, dashboards and student portals are served over HTTPS, so information travelling between a browser and KlasPoint is encrypted in transit.

This page describes security controls built into the KlasPoint product. It is not a certification or an audit report.

Run your centre on a platform built with care

Set up KlasPoint for your tutorial centre today.