Security & Compliance

Password Policy

The password, authentication and multi-factor requirements that protect Skoolfly accounts.

1. Policy Statement

Passwords and authentication credentials are a first line of defence for the Skoolfly platform. This policy establishes requirements for creating, storing, changing and protecting passwords, and governs the use of additional authentication measures.

2. Purpose

The purpose of this policy is to reduce the risk of unauthorised access to Skoolfly systems and data through weak, reused or compromised credentials.

3. Scope

This policy applies to all users of Skoolfly systems, including employees, contractors, administrators and external users such as school administrators, teachers, students and parents, as well as any system service account or credential used to access Skoolfly infrastructure.

4. Password Requirements

Passwords should be created to balance security with usability. Where the platform allows, Skoolfly applies the following baseline requirements.

LengthPasswords should be at least 12 characters long where supported.
UniquenessPasswords must not be reused across different systems or accounts.
PredictabilityPasswords must not be based on easily guessed information, such as names, birthdays, usernames or common words.
PassphrasesUse of long, memorable passphrases is strongly encouraged.
Previous passwordsUsers should not revert to recently used passwords.
Password managersUse of an approved password manager is encouraged so that each account has a unique, strong password.

5. Account Lockout and Failed Attempts

Accounts may be temporarily locked after repeated unsuccessful login attempts to reduce the risk of automated guessing.

Locked users must follow the approved recovery or reset process.

Security events related to failed or unusual login attempts should be reviewed and, where appropriate, reported in accordance with the Incident Response Policy.

6. Password Storage

Passwords must never be stored in plain text.

Passwords are hashed using an approved, cryptographically strong algorithm and salted.

Credentials must never be shared in emails, chat messages, tickets or other unsecured communications.

Hard-coded or embedded credentials in code, scripts or configuration files are prohibited.

7. Password Changes and Resets

Passwords should be changed promptly where compromise is suspected.

Reset links and recovery codes are time-limited and single-use.

Reset attempts must confirm the user's identity through an approved verification process.

System and service accounts use securely generated, rotated credentials rather than shared human passwords.

8. Multi-Factor Authentication

Multi-factor authentication (MFA) is strongly encouraged for all users and is required for privileged and administrative access to Skoolfly systems. MFA adds a second verification factor beyond the password, significantly reducing the risk of account takeover.

9. Prohibited Practices

Sharing passwords with other people.

Writing passwords on paper where they may be seen.

Submitting passwords through non-approved sites or apps.

Using the same password for Skoolfly and personal accounts.

Storing passwords in unsecured documents or cloud notes.

Sending passwords by email, chat or text message.

10. Roles and Responsibilities

UsersCreate and protect strong, unique passwords and promptly report suspected compromise.
AdministratorsEnforce this policy, manage resets, and investigate authentication anomalies.
EngineeringMaintain secure authentication, hashing and recovery mechanisms.
Security OwnerReviews and updates this policy and related controls.

11. Compliance and Enforcement

Non-compliance with this policy may result in loss of access or disciplinary or contractual action where appropriate. Controls may be enforced administratively (for example, through minimum-length or MFA requirements) where the platform supports them.

12. Review

This policy is reviewed at least annually, or when significant changes in authentication technology or threat practices occur.