Center data isolation
Tenant scope fails closed when no tenant context is available.
Security across core product layers
Access control starts at center and branch boundaries, with sensitive activity recorded in immutable history.
Tenant scope fails closed when no tenant context is available.
Policies verify the user’s branch access again.
Permissions are configurable and independent of role names.
User, time, IP, and before-and-after changes are recorded.
Payments and ledger entries are corrected by reversal, not direct deletion.
Private uploads remain disabled until storage and scanning policies are complete.
Production must only be served through valid TLS.
Backup and restore are documented; automation and monitoring must be verified per environment.
Secure sessions, login rate limits, and separate guards are implemented.
Tenant, branch, permission, and financial-record tests are part of the suite.
TLS, backups, Redis, queues, log rotation, and monitoring must be checked and documented in every deployment.
Clear management, better-organized learning
Manage enrollment, classes, attendance, fees, and reports through one clear workflow.