Security & Privacy
Security is part of Cymbari's architecture from the beginning.
Cymbari's security roadmap includes identity verification, server-side authorization, organization isolation, audit logging, protected files, rate limiting, connector permissions, and integration-specific security testing.
A
Authentication
Verified-email accounts, organization membership checks, student sign-in architecture, session handling, and access-revocation controls.
Z
Authorization
Server-side checks, role boundaries, school and district isolation, cross-organization protections, and default-deny integration permissions.
D
Data Boundaries
Production student and assessment records are designed to live in secured backend services rather than relying on browser-only local storage.
Development posture
- Synthetic data only during current development and demos.
- Real student data is only introduced through an authorized organization-level pilot.
- Security, privacy, procurement, legal, and data-governance review are explicit launch gates.
- Software dependency findings are tracked and must be addressed before production launch.
This page is a high-level security overview, not the final district security package. Before production rollout, Cymbari's district security package will include detailed architecture, data-flow, retention, incident-response, subprocessor, student privacy, AI, and data-processing materials.