Security & Privacy

Security is part of Cymbari's architecture from the beginning.

Cymbari's security roadmap includes identity verification, server-side authorization, organization isolation, audit logging, protected files, rate limiting, connector permissions, and integration-specific security testing.

A

Authentication

Verified-email accounts, organization membership checks, student sign-in architecture, session handling, and access-revocation controls.

Z

Authorization

Server-side checks, role boundaries, school and district isolation, cross-organization protections, and default-deny integration permissions.

D

Data Boundaries

Production student and assessment records are designed to live in secured backend services rather than relying on browser-only local storage.

Development posture

  • Synthetic data only during current development and demos.
  • Real student data is only introduced through an authorized organization-level pilot.
  • Security, privacy, procurement, legal, and data-governance review are explicit launch gates.
  • Software dependency findings are tracked and must be addressed before production launch.
This page is a high-level security overview, not the final district security package. Before production rollout, Cymbari's district security package will include detailed architecture, data-flow, retention, incident-response, subprocessor, student privacy, AI, and data-processing materials.