Your data, kept apart.

A school's records are its most sensitive asset. Here is where they live, how Aurora keeps them separate from every other school, and who can see them.

Hosted in the cloud, separate for every school

Your school's data lives on Aurora's cloud servers, not on the school's own computers. Each school gets an environment of its own, with its own services and its own databases. No school's records sit inside another school's database, and no single shared database holds everyone's roll.

Student records, fees, results and staff access each have one owner inside the school. Other screens read from the owner and never keep a second copy of the truth.

Who can see what

Every request is checked on the server against explicit permissions and the school it belongs to. Hiding a button is never the protection. Aurora Console has three access profiles: administrator, Principal and Accountant, and the same single sign-in opens every room.

A record of everything

Changes are recorded in the room that owns them, in an append-only history. A separate audit view lets an authorised person ask what happened across Aurora in a given window, and each entry links back to the record it describes.

The audit view is a read-only projection. It points at the truth; it does not replace it.

What Aurora's own team can see

Aurora care manages updates and checks health. It knows how large a school is and whether its services are running. The care console does not keep a copy of your student roll, your fee ledger or your marks.

A school reports to the care console with restricted, credential-bound summaries: counts and health signals. If the care console is unavailable, your school's own services keep running.

Access to Aurora's own management console requires multi-factor sign-in, and what each of our operators may do is limited by role.

Updates and backups

Updates are versioned and signed. They are installed one school at a time and recorded, so we can say exactly what is running where.

Backups and health censuses are created when a school is created. A school is protected because it was set up that way, not because somebody remembered afterwards. We check backups by restoring them and comparing row counts against the original, and we keep that evidence.

Six questions to ask any school software vendor, including us

  1. Where exactly do our records live, and who else is in that database?Ours: on Aurora's cloud servers, in an environment kept for your school alone, with no other school's records beside yours.
  2. Who at your company can read them?Ours: the care console that manages updates holds counts and health, not records.
  3. What happens to our school if you have an outage?Ours: if the care console is unavailable, your school's services keep running.
  4. How do updates reach us?Ours: signed, named, one school at a time.
  5. How do you know a backup works?Ours: we restore it and compare it with the original.
  6. What is live today, and what is only planned?Ours: every room is labelled on the features page.

Want the detail for your governing body?

We are happy to walk through how a school is installed, backed up and updated.