Security and Data Protection

Cybersecurity and Data Protection in ViewClass

ViewClass treats data protection, permission management, cloud hosting, and backups as core elements in running the platform, not optional extras. ViewClass commits to applying high standards of data protection and cybersecurity, with transparency in describing what it does and what requires complementary operational responsibility from the school — without absolute promises that cannot be technically guaranteed.

ViewClass Security Principles

The pillars we follow in data protection, access governance, and service continuity.

  • High Standards in Data Protection and Cybersecurity

    We commit to applying high standards of data protection and cybersecurity, with our controls and procedures updated in line with approved best practices.

  • Need-to-Know and Permission-Based Access

    Each user's access is limited to what their role requires, and this governance reduces unnecessary access to data.

  • Per-School Data Separation

    Each school's data is organized separately according to the approved hosting model, supporting clarity of operational scope per school.

  • Service Continuity via Daily Backups

    Daily system backups support service continuity and handling of operational situations.

  • Internal Accounts Rather Than External SSO by Default

    Each user has an internal account with a username, password, and role-based permissions, with integration and access requirements open to study based on the school's needs.

  • Considered Integrations via APIs

    Integrations with systems supporting the learning process or educational content are arranged according to activation scope and technical requirements within the technical and commercial proposal.

Trust and Accreditation

Accreditation is a trust factor, not an absolute security promise.

ViewClass is a Saudi educational platform accredited by the National eLearning Center under accreditation certificate Q17192514. This accreditation reflects ViewClass's commitment to locally approved requirements for educational platforms and is an important trust factor for the school's decision committee and compliance officers. While important, this accreditation is not converted into an absolute security promise, since the digital environment is inherently subject to change, and accreditation is complemented by an ongoing operational approach to data protection and cybersecurity.

  • A Saudi platform accredited by the National eLearning Center.
  • Accreditation certificate number: Q17192514.
  • Accreditation is a trust factor supporting the school's evaluation without replacing detailed technical assessment.

Our Approach to Data Protection

Clearer permission governance and reducing unnecessary access.

ViewClass's approach to data protection starts from the principle of organizing access by role: no user sees anything beyond the tools and data needed for their work, and access to anything outside their responsibilities is not granted. This reduces data exposure to unwanted operations and makes accountability within the school easier to track. It is complemented by handling data according to operational and service needs, without unnecessary expansion.

  • Organizing data access on a need-to-know and permission basis.
  • Managing permissions by role for each user.
  • Reducing unnecessary access to data.
  • Handling data according to operational and service needs.

Accounts and Role-Based Permissions

Every user has their own account, and every role has its own permissions.

ViewClass relies on an internal accounts-and-permissions system for each user: an account with a username, password, and role-specific permissions (system manager, principal, teacher, student, parent, supervisor, counselor, activity leader, cafeteria officer, clinic officer). At the central level, there is a Super Admin to create schools and configure the general framework. At each school's level, every school has an independent system manager with permissions to manage their school only, so each officer's scope remains clear.

  • An independent account for each user with role-based permissions.
  • A central Super Admin for creating schools and configuring the general framework.
  • An independent system manager per school managing only their school's permissions.
  • Clear separation in responsibility scope between roles.

Cloud Hosting and School Separation

An architecture that hosts each school's data according to the approved hosting model.

ViewClass data is hosted on cloud servers, according to ViewClass's approved hosting model so each school has its own environment. This model supports clarity of operational scope for each school and organizes its data separately from other schools. This page does not disclose infrastructure details or hosting providers; IT managers can discuss the appropriate details for their school within the technical and commercial proposal or in a direct meeting.

  • Cloud hosting for the platform's data.
  • A dedicated environment per school according to the approved hosting model.
  • Clear separation in organizing each school's data from others.
  • Infrastructure details are discussed within the technical and commercial proposal or in a direct meeting.

Daily Backups

A pillar of service continuity and handling operational situations.

System backups are performed daily as part of ViewClass's operational procedures. This supports service continuity and the team's ability to handle operational situations as the case requires, without turning this measure into an absolute promise to prevent data loss under all circumstances. Best practices for handling data on the school's side remain a complementary part of this measure.

  • Daily system backups.
  • Support for service continuity and handling operational situations.
  • Backups alone are not an absolute guarantee against data loss.

Integrations and APIs

Considered integration with systems supporting the learning process.

ViewClass provides APIs to integrate with platforms that support the learning process or educational content within schools. Integrations are arranged according to the activation scope and technical requirements within the technical and commercial proposal; no unconfirmed integrations are listed here. Studying integration and access requirements remains open to discussion based on the school's needs and the systems it uses.

  • APIs for integration with systems that support the learning process and educational content.
  • Integrations are arranged according to activation scope and technical requirements.
  • Studying integration requirements within the technical and commercial proposal.

Login and Virtual Classrooms

One account per user inside ViewClass.

ViewClass relies on internal accounts: each user has an account with a username, password, and role-based permissions. ViewClass does not rely on external SSO by default, and integration and access requirements can be studied based on the school's needs and the systems it uses. When creating a virtual classroom, the teacher uses their ViewClass account directly without needing a new username and password for the virtual classroom, after settings have been pre-configured by the system manager, keeping the teacher's operational flow smooth and unified.

  • An internal account per user with role-based permissions.
  • ViewClass does not rely on external SSO by default.
  • The teacher uses their ViewClass account to create the virtual classroom after settings have been pre-configured.
  • Studying integration and access requirements is possible based on the school's needs.

IT Manager Checklist

Ready-made questions an IT manager can use when evaluating ViewClass within the school.

  1. 1. How are permissions managed within the school?

    To understand the role structure, Super Admin, school system manager, and the scope of permissions per role.

  2. 2. How are accounts prepared and users onboarded?

    To learn about adding via form, Excel, or Excel files exported from Noor when available.

  3. 3. What is the cloud-hosting scope and per-school data separation?

    To understand the approved hosting model without disclosing sensitive infrastructure details on the public website.

  4. 4. What is the daily backup mechanism?

    To understand its role in service continuity and handling operational situations.

  5. 5. What integrations are needed via APIs?

    To discuss systems supporting the learning process or educational content within the activation scope.

  6. 6. Who holds administrative permissions within the school?

    To define the school's system manager and the permission-separation mechanism between roles.

Discuss Your School's Security and Integration Requirements

Request a customized technical and commercial proposal outlining what concerns your school in permissions, hosting, backups, and integrations, or book an online meeting to discuss the details with our team.

Frequently Asked Questions

We commit to applying high standards of data protection and cybersecurity, with access organized on a need-to-know and permission basis, reducing unnecessary access, and continuously updating our controls and procedures in line with approved best practices.