Host resolution first
Sign-in does not start before the target school is known.
Security
The school context is selected before authentication, then connections, storage, and permissions operate inside the correct boundary.
The school host is resolved first, then the database connection, storage namespace, and authentication context are selected.
Sign-in does not start before the target school is known.
School models use a contextual, dedicated connection.
The interface is not the security boundary; the server enforces decisions.
Paths and cache keys belong to the active school context.
Custom domains activate only after control is proven.
Time-bounded, scoped, and audited support sessions.
Suspension, recovery, and retention without silent data deletion.
Sensitive control-plane actions produce reviewable records.
Hosting and compliance
We do not publish an unapproved region or provider. Location and compliance requirements are set during deployment planning.
The SaaS design connects each school to a separate database and selects that connection after host resolution.
We will explain request resolution, connections, authorization, and support boundaries without unverified claims.