Security information

Protected by design.

Pastoral Hub is designed for authorised school staff. Public product information is separated from protected school workspaces, and access to student-support information is controlled through authentication, role permissions and server-side checks.

HTTPS only

Encrypted web access

Pastoral Hub is served over HTTPS. The service uses HTTP Strict Transport Security so supported browsers continue to use encrypted connections.

Authenticated

Approved staff access

Protected school workspaces require approved authentication. Access is not granted simply because someone knows a workspace URL.

Role scoped

Permission boundaries

Access can be limited by staff role, year level and operational responsibility. Sensitive actions are checked at the server boundary, not only hidden in the interface.

Private by default

No public student records

The public Pastoral Hub website contains no student records, pastoral notes, attendance data, behaviour information or academic results.

Browser protection

Security headers

Pastoral Hub uses controls including HSTS, frame protection, MIME-type protection, a restrictive permissions policy and a Content Security Policy to reduce common browser-based risks.

School scoped

Separate workspaces

School workspaces are separated from the public website. School administrators control approved users and role assignments for their environment.

Security reporting

If you believe you have found a security issue, do not include student information, credentials or sensitive school data in an initial report. Use the service administrator or school contact responsible for your Pastoral Hub workspace. Automated security-disclosure information is published at:

https://pastoralhub.co.nz/.well-known/security.txt