Role-based access — staff see only what they should
Every Dock user is assigned a role — Admin, Registrar, Finance Officer, Admissions Staff, or Parent. Each role sees only the data and actions appropriate to it. A finance officer can't touch enrollment records. An admissions staffer can't see the ledger. A parent sees only their own child's application and payment status.
✓ Role-scoped data access
Enterprise cloud infrastructure, behind Cloudflare
The same infrastructure stack trusted by governments and Fortune 500s — enterprise-grade DDoS protection, a global CDN, and Cloudflare's WAF in front. Not the shared cPanel model that enabled 2026's multi-school pivot attacks.
✓ Enterprise infrastructure
Tenant isolation — your data is yours alone
Every school's data lives in its own logically isolated database partition. Queries are scoped to a single school's partition at the data layer, not by application-level policy alone.
✓ Logical tenant isolation
Field-level encryption for sensitive data
Financial records and sensitive personal information are encrypted at the field level (AES-256-GCM) — not just at rest. PII is architecturally separated from authentication records.
✓ AES-256-GCM encryption
Complete audit trail on every action
Every administrative action, financial transaction, and record change is logged with who did what, when. Accountability for every peso and every approval decision — and an evidence trail you can put in front of a regulator.
✓ Full audit logging
Built to support your RA 10173 obligations
Consent captured and versioned at enrollment. Audit logs aimed at the Data Privacy Act's accountability principle. Data retention controls baked in, not bolted on. Your school remains the personal information controller and holds its own compliance obligations; Dock is the processor.
✓ Versioned consent & audit trail
OTP verification for sensitive actions
Document uploads, sensitive applicant edits, and payment confirmations are gated behind OTP verification — reducing exposure even if a session is compromised.
✓ OTP-gated sensitive actions