Home / Security & privacy
For the IT lead · Security & privacy

Who can see what, and how you prove it.

Your school’s records kept apart from every other school’s, access granted by role down to the page, and a record of who did what that nobody can edit. This page says how Commun holds children’s data, where it lives, and what happens if something goes wrong — in the order an IT lead asks.

Who sees what

Access by school first, then by role

Every record carries the school it belongs to, and every question the system asks is filtered by that school before it reaches the database. Inside the school, access is granted by role, to the page.

One school never sees another

The separation is in the way the data is read, not in a setting anyone can switch off. A school account has no cross-school view, and a question asked inside one school cannot return another school’s students, bills or marks.

More than a hundred named permissions

Grouped into the roles a school actually has — Owner, Finance, Academic Admin, Admission — and yours to change. Printing a student ID card is its own permission, separate from viewing the student, and approving a bill is a permission of its own.

Governed, not typed

A student does not become active because someone typed it. Placement is confirmed, a status change is approved, and offboarding is approval-gated — three separate permissions, so a board can say who holds each one.

The questionWhere the answer is kept
Who changed this bill, and when? Audit Trail — every change, with the person and the time, and no way to edit an entry.
Who signed in from a new phone last night? Login Log — the credential used, the device, how the code was sent, and whether it worked.
Who can print an ID card, approve a bill, read the log? Roles and permissions — each is a named permission you grant by role, and reading the Login Log is one of them.
Who opened that safeguarding report? The report’s own access log — one line every time its content was served, kept for as long as the record is. Only the safeguarding leads on the roster can open a report at all.
Which outside system read our student records? The connected system’s record — its own key, what that key may do, and an append-only log of the key being issued, rotated or revoked.
Did anyone from Commun look at our school? Recorded, against the person who made the visit — including a member of Commun’s own staff acting on your instruction.
Sign-in

No password to steal, and none to share

Staff and families sign in with a one-time code, by e-mail or phone. There is no staffroom password on a sticky note, nothing to reset in September, and nothing for a leaver to take with them.

What a sign-in leaves behind

Every attempt is written to the Login Log, whether or not it succeeded — and reading that log is a permission of its own.

  • The credential used, the device, how the code was sent, and the outcome
  • A code is burnt after five wrong guesses; a fresh one can be requested three times before the sign-in starts over
  • A leaver’s access ends with their account; the audit trail keeps their name on everything they did while they had it
  • The signed-in session travels only over an encrypted connection, in a cookie that scripts on the page cannot read
Login LogRead only
Today · 7.42 am [email protected]Form tutoriPhone · SafariCode by e-mail Signed in
Yesterday · 10.15 pm +60 12-345 6789GuardianAndroid · ChromeCode by WhatsApp 5 wrong codes · burnt
Yesterday · 9.03 pm [email protected]Finance ManagerWindows · EdgeCode by e-mail Signed in

The columns are the product’s; the people are invented.

The record

Every change has a name attached, and nobody can edit the record

A discount applied, a mark amended, a bill written off, a permission granted — the entry outlives the person who made it, which is what a board and an auditor both want.

Harmony AcademySchool Admin · Audit Trail
Priya Menon · Head of School
School Admin Students Academic Finance Insight Centre Audit trail Roles

Activities29 August 2026

Action Performed by Performed at Full details
0 activities Read only

Mirrors: School Admin → Audit Trail → Activities

The audit trail is read-only by construction: there is a permission to read it and none to change it. Entries older than a year move into an archive rather than being deleted, so the trail behind a bill from three years ago is still there when the auditor asks. Safeguarding records keep a separate log of every time a report’s content was opened, and that log is kept for as long as the record is — which is deliberately much longer.

Where it lives

Singapore, encrypted on the way, backed up without anyone remembering to

Your school’s records are stored in Singapore — an hour from Johor Bahru rather than on the other side of the world — and handled under Malaysia’s Personal Data Protection Act 2010.

In transit

Every page, every request from the app and every file moves over an encrypted connection. A plain address is sent straight to the encrypted one; there is no unencrypted way in.

Files at rest

Documents, proof-of-payment slips and photographs are encrypted where they are stored. Anything that is school data — attachments, proofs, CRM media — is opened only through a permission-checked link that expires within minutes.

Backed up

Copies of your records are taken automatically and kept apart from the running system, and a restore point is taken before a release goes out.

Watched

Commun is built to be available at all times. Faults are reported to us the moment they happen and worked through one by one, and the days everyone logs in at once — results day, the first week of term — are the days we plan the year around.

Kept only as long as needed

Rendered copies of notices are cleared after six months and the audit trail moves to the archive after a year. Safeguarding records are the exception, kept for as long as the child might need them.

Deleted when you leave

On termination the school exports its records and Commun deletes them from active systems. A full deletion takes the files with the rows.

The Act

Your school is the controller. Commun is the processor.

For the records in your tenant, the school decides and Commun acts on its instruction — so the notice, the agreement and the breach commitments are written for your Data Protection Officer to read, not only for ours.

The notice

Issued in English and in Bahasa Malaysia, as the Act requires: what is processed, why, with whom it is shared, and the rights you have over it. Read it in English or in Bahasa Malaysia.

The agreement

A data processing agreement is signed with every school. Its breach clause is the commitment below, and the assessment covering the transfer of your data to Singapore is yours on request.

If something goes wrong

We tell your school within 24 hours, help with the 72-hour notification to the Commissioner and the 7-day notification to families, and keep a register of incidents for at least two years. The commitments, in full.

A named officer

Commun’s Data Protection Officer is registered with the Personal Data Protection Commissioner, and is the address for a security report as much as for a rights request.

The IT lead asks

The questions we are asked before a school signs

Can we get our data out?

Yes. The student roster exports to CSV with the columns you choose; bills, payments, tax, deposits, write-offs and enrolments export from the Insight Centre; statements of account are per family. On termination the school exports its records before Commun deletes them.

Who at Commun can see our school?

Access within Commun is limited to the staff who support the service, and they are bound by confidentiality. When one of them opens a school’s portal, the visit is recorded against their name.

Do you support single sign-on?

Between Commun and AccessPoint, in effect: a member of staff opens AccessPoint from Commun already signed in, and only staff can make that crossing. Commun does not sign in through a school’s own identity provider today; staff and families use the one-time code.

Is there an API?

An open API and registered connected systems are an add-on. Each system gets its own key with stated abilities, every call it makes is logged, and issuing, rotating or revoking a key is written to an append-only log.

Does the data leave Malaysia?

It is stored in Singapore. Some service providers, such as messaging, may process data in other countries; each transfer is assessed against section 129 of the Act as amended, every recipient is bound by contract, and a school may ask for the assessment covering its data.

Can a parent see another family’s child?

No. A parent sees the children the school has linked to their account and nothing else, and a request to link another child is approved by the school, not by the parent.

Bring your IT lead to the demo

Half an hour on the pillar your office lives in, with the questions on this page answered on the screens themselves — the audit trail, the Login Log, the roles.

Book a demo