Security & Compliance
Employee Security Policy
The security expectations and responsibilities that apply to everyone working at Skoolfly.
1. Policy Statement
People are a critical part of Skoolfly's security posture. This policy sets out the security expectations for employees, contractors and other personnel, covering recruitment, onboarding, conduct while working, and offboarding.
2. Purpose
The purpose of this policy is to reduce human-related risk, protect the data and systems personnel handle, and create a culture where security is understood as everyone's responsibility.
3. Scope
This policy applies to all employees, contractors, interns, consultants and any other person granted access to Skoolfly systems or information, regardless of location or employment arrangement.
4. Recruitment and Background Checks
Roles that involve access to sensitive data or systems are subject to appropriate background screening where legally permissible. Candidates are informed of applicable security obligations, and key roles execute confidentiality and security agreements.
5. Onboarding
New personnel complete security induction before or promptly after gaining access.
Accounts are provisioned on a least-privilege basis in line with the Access Control Policy.
Personnel acknowledge their obligations under the Acceptable Use Policy and this policy.
Devices and tools are issued or approved in line with security standards.
6. Offboarding and Transfers
On termination or resignation, access is revoked promptly and keys, credentials and assets are recovered.
Confidentiality obligations survive the end of employment or contract.
On role transfer, access is reviewed and adjusted to the new role.
Company data is not taken to personal accounts or devices.
7. Confidentiality
Personnel must keep sensitive and confidential information private, including personal data, customer information, commercial information and security details. Information is shared only on a need-to-know basis and through approved channels in line with the Acceptable Use Policy.
8. Device and Endpoint Security
Work devices are protected by strong authentication, encryption where supported, and current security updates.
Devices are locked when unattended and not left exposed in public places.
Company software is installed from approved sources.
Suspected compromise of a device is reported immediately.
9. Email and Phishing Awareness
Personnel are alert to phishing and social engineering and verify the identity of unexpected senders.
Report suspicious messages rather than acting on them.
Do not disclose credentials, verification codes or personal data in response to unsolicited requests.
10. Remote and Hybrid Work
Personnel working remotely follow the same security expectations as on-site. They should use approved connections and devices, protect portable devices and data, and avoid working with sensitive information in public where it can be observed.
11. Information Handling
Personnel handle information according to its classification, as set out in the Information Security Policy. Sensitive data is stored in approved systems, transmitted through secure channels, and disposed of securely when no longer needed.
12. Training and Awareness
Personnel receive security training appropriate to their role, refreshed periodically. Security awareness is promoted through internal communication and after notable security events.
13. Reporting and Disciplinary Action
Personnel should report security concerns and incidents without delay. Deliberate or negligent breach of this policy may lead to corrective action, including disciplinary measures up to and including termination of employment or engagement, subject to applicable law.
14. Review
This policy is reviewed at least annually, or when working practices or security requirements change significantly.
