Security
Secure files on the student record

Confidential documents. Encrypted, audited, for the right eyes only.

Secure files is the encrypted vault on every student record. Psychologist notes, SEN reports, health documents, legal letters and productivity files live in one place — with role-based access, signed URLs and full edit history.

Get started
Features

What you get

RPC-gated access

Every view goes through the `can_access_student_secure_files` chokepoint. Psychologist notes stay confidential — only the author and school admin can see them.

Encrypted private bucket

Files live in the private `student-secure-files` bucket. No public links — only short-lived signed URLs issued on click.

Edit history

Every session logs open time, duration, number of edits and the user. Open the full history with one click from any file row.

Six categories

Psychologist, SEN, Health, Legal, Productivity and Other. Filter quickly — and keep confidential records separate from a pupil's daily work.

Two file types

Upload a PDF, image or document — or link an existing productivity file (Docs, Sheets, Slides) without ever moving data off the platform.

Role-based visibility

School admin, psychologist (own notes), SEN consultant and explicitly assigned staff. Parents and pupils only ever see what is shared with them.

End-to-end flow

How it works

1. Upload or link

Drag in a PDF, or link an existing Doc/Sheet/Slide. Pick a category — Psychologist, SEN, Health, Legal, Productivity or Other.

2. Access decided by RPC

On every view the client calls `can_access_student_secure_files`. The result drives the tab, the list and the signed URL.

3. Tracked editing

`SecureFileEditTracker` records each session: user, opened-at, duration and edit count. History is one click away from the file row.

4. Deletion with audit trail

Deletion requires an explicit action and leaves an audit trail — so you can document both who saw what, and when something was removed.

Compliance

Built for confidential pupil data

Psychologist confidentiality

Journal notes have their own RLS and audit. Only the author psychologist and school admin — never teachers or parents without explicit sharing.

No AI exposure

Files are never sent through AI models. Secure files sit outside the prompt pipeline and are excluded from analysis and training.

GDPR & data minimisation

EU-hosted, signed URLs, short lifetimes and role-based access. Follows the same Privacy-by-Design patterns as the rest of the platform.

Full audit trail

Every open, edit and deletion is logged. School leadership can document access for inspections and the DPO at any time.

Keep confidential files in one place

Encrypted, audited and role-based — without moving data off the platform.