Security
senco uses authenticated workspaces, organisation-scoped records, role-aware team administration, and protected API routes for student, observation, report, and escalation workflows.
Magic-link authentication is delivered through transactional email, with server-side audit events for student creation, report generation, escalation detection, acknowledgement, and resolution.
Before production rollout, configure a verified sending domain, enforce operational access policies, and review hosting, database, backup, and incident-response arrangements against school data obligations.