Security overview
Protecting school-managed accounts
Last updated: September 6, 2026
Waypoint Pass uses HTTPS, hosted authentication, role-based database policies, school-separated records, single-use setup codes, and verified email password resets. Security settings are reviewed before production use.
What schools should do
- Approve every account before it can access a school workspace.
- Use unique passwords and enable multi-factor authentication for owner and school-admin accounts.
- Remove accounts when staff or students no longer need access.
- Do not include sensitive information in pass notes or support requests.
Report a concern
Users should report a suspected unauthorized account, data exposure, or security issue to their school administrator immediately. Schools should use their established Waypoint Pass owner contact and avoid including student information in the initial report.
Before production use
Each school should complete its own vendor-security review and confirm the service agreement, data-processing terms, incident contact, backups, retention, and account-management procedures.