What this page is
ZenXSchool is a school software product operated by SoftAge Systems, Inc. d/b/a ZenXSchool. This page describes the security design of the ZenXSchool school platform: tenant isolation, signed-in staff access, role-based permissions, audit records, and encryption in transit.
SoftAge Systems, Inc. d/b/a ZenXSchool publishes this so a school can see how the workspace is meant to be protected. It is not a SOC 2, ISO, FERPA, or other certification, audit report, or compliance mark unless we separately confirm a current attestation in writing.
Capabilities can vary by configuration, rollout, and a signed Order. Security is a shared responsibility with the school that administers the workspace.
School data stays with the school
ZenXSchool is built as a multi-tenant platform with separation between organizations. A school’s users, academic records, calendars, finance documents, and other operational records remain associated with that school’s workspace.
An education group can have oversight without mixing one school’s records into another. White-label branding does not move data across school boundaries.
Designed for
- Tenant-scoped school data
- Organization-specific access
- Role-based permissions
- Auditable administrative activity
Authentication
Staff reach the workspace through a signed-in session. The platform supports password authentication, session management, account recovery, and additional controls the school can configure.
Platform capabilities include
- Secure sign-in and session expiration
- Password hashing and account recovery
- Email verification for new accounts
- Multi-factor authentication where the school enables it
- Passkeys and single sign-on where configured
Availability of multi-factor authentication, passkeys, and single sign-on depends on how the school’s workspace is configured. Do not assume every control is on for every tenant.
Roles and permissions
Not every person in a school should see every record. ZenXSchool uses permission-based access so a school can decide what users can view and what they can change.
Privileged controls — add, edit, delete, grant, manage — are meant to appear only for people who hold the matching permission. The server still enforces those permissions.
Schools can typically control access by
- Role and assigned permissions
- Module and feature
- Administrative versus operational work
Access and audit records
The platform keeps access logs and audit activity so a school can see who signed in and who changed administrative or operational records, subject to retention and the permissions of the people reviewing those logs.
Encryption and infrastructure
Connections to the website and the signed-in application use TLS in transit.
Customer Data is stored in databases and object storage we operate or that subprocessors operate under contract. Encryption at rest is used on the infrastructure we provision.
Hosting, email delivery, file storage, document rendering, and bot defense may be provided by contracted service providers who may process data only to deliver those services.
Education records
When a school stores education records in ZenXSchool, the school remains the educational agency or institution responsible for those records. SoftAge processes them as a service provider to that school.
This page does not certify FERPA, COPPA, or any other education-privacy framework. See the Privacy Policy for how we describe controller and processor roles, and the Terms of Service for the school’s responsibilities.
Questions and incidents
Security questions and suspected incidents: info@softage.com. Include “ZenXSchool security” in the subject and enough detail for us to identify the workspace. If you believe an account is compromised, say so in the first line.