Start Free Trial
One tenant, two ladders

Matric and O Level, side by side

A school running a national stream and a Cambridge stream runs both in one CampusFlo tenant β€” separate ladders, separate grading, one student record.

See how it works
Also configured
USA, India, Gulf, IBPages coming shortly
9 profiles

Configuration, never a fork

A profile sets the level ladder, term structure, grading scheme, attendance model and the vocabulary itself. Every value stays editable afterwards.

One product, every country
40 minutes

See it on your own scenario

A screen-share run against your levels, your grading scheme and your board β€” not a slide deck. Bring your student count and campuses.

Schedule a demo
Why CampusFlo Blog About Contact Start Free Trial

Security and data protection

A school system holds medical notes, safeguarding concerns, custody arrangements and exam results. Access is granted per action, masked per field, and audited on every view.

How access actually works

Permissions are per action, not per screen, and sensitive categories each sit behind their own permission rather than inside a general staff role.

Field-level masking

A role sees the fields its job needs. Others are hidden rather than read-only, and never appear in exports.

Restricted record types

Health, inclusion, safeguarding and counselling each carry their own permission, separate from general staff access.

Access audit

Opening a sensitive profile is recorded. Concerns cannot be deleted, only voided with a reason and an author.

Scoped by assignment

A subject teacher sees their own groups. A campus head sees their campus. Consolidated views need a head-office role.

Role templates

Roles ship as templates with sensible permission sets and are tenant-configurable, so you are not accepting somebody else’s idea of who sees what.

Write-only logging

Any member of staff can log a safeguarding concern. Reading them back is restricted to the designated lead.

What a family can ask for, and what you can produce

Data-protection rights are workflows in the product rather than a policy document someone has to satisfy by hand.

Rights and consent

  • Consent captured against the record, per channel and per category
  • Subject-access export for a student or a guardian
  • Erasure requests with a defined workflow
  • Retention rules that run as scheduled jobs
  • Opt-outs honoured automatically in every audience

Framework alignment

  • Education-records access configurable per profile β€” FERPA in the US
  • GDPR access and erasure rights for the UK and EU
  • Safeguarding access restrictions aligned to KCSIE in the UK
  • Court-order and custody flags enforced in the parent portal
  • Bilingual privacy text where a second language is configured

What we do not claim

Security pages are where vendors are most tempted to imply more than they hold.

CampusFlo does not hold ISO 27001, SOC 2 or any equivalent certification, and this page will not imply otherwise. What is described above is how the product behaves, which is verifiable in a demo rather than in a certificate.

Hosting, backup arrangements and data residency depend on how your institution is deployed, and we will answer those specifically on the call rather than generically here. If your board or regulator requires a particular arrangement, tell us early β€” it is a reasonable thing to require and a poor thing to discover late.

Questions procurement asks

Who can see a child’s medical information?
Teachers see an emergency summary β€” allergies, conditions and the emergency contact, which they have a duty of care to know. Full medical detail, medication logs and care plans sit behind a separate permission held by the nurse and authorised staff. Every access to a health profile is recorded.
Can a member of staff delete a safeguarding record?
No. Concerns cannot be deleted, only voided with a reason and an author, and the original stays in the chronology. Reading concerns back is restricted to the designated safeguarding lead; logging one is open to any member of staff so that reporting is never blocked.
How are separated families with a court order handled?
Custody and court-order flags are set on the student record and enforced by the parent portal, so a guardian whose access is restricted does not see that child. It does not depend on staff remembering the arrangement.
Do you hold ISO 27001 or SOC 2?
No. We would rather say that plainly than imply otherwise. What the product does β€” field-level masking, per-action permissions, restricted record categories, access auditing, consent capture, export and erasure workflows β€” is demonstrable in a demo.
Where is our data hosted?
That depends on your deployment, and it is a question we answer specifically rather than generically. If your board or regulator requires a particular residency arrangement, raise it at the first call.

Bring your procurement questions to the call

Data-protection questions are better answered against a live tenant than a PDF. Bring the list.

Schedule a demo