Security
Security designed around real education operations.
ACT Tuition uses layered controls for applications, portal accounts and internal operations. This page describes the controls built into the platform; it does not claim external certifications that have not been verified.
Authentication
Password hashing, secure sessions, login throttling, password-reset tokens and forced password change for newly issued portal accounts.
Role access
Role-scoped portal access separates administrative, tutor, student and parent information. Access checks are enforced server-side.
Application security
Server-side validation, honeypot anti-spam controls, protected PDF storage and prepared database statements.
Auditability
Important portal actions can be recorded in the audit log, including logins and changes to operational records.
Private files
Configuration, database definitions, application storage and internal tooling are blocked from direct public web access.
Data minimisation
ACT should collect only information required for tuition, matching, support, safeguarding, billing or lawful operational needs.
Enterprise review
Need security information for procurement?
Schools, universities, companies and public organisations can use the Procurement Centre to request the security/privacy information relevant to a proposed programme.
Procurement Centre →