Academiq

User guide

Security, audit and recovering data

Two-step login, the activity log, restoring deleted records, and how your data is kept separate.

In short. Turn on two-step login. Deleted records go to a trash you can restore from. Significant actions are written to an activity log. Your school's records are separated from every other school's.

Two-step login

Two-step login (2FA) asks for a code from your phone as well as your password. It is available to every user — administrators, teachers, students, parents, staff and accountants — and is set up from account settings.

Turn it on for administrator accounts at minimum. An administrator account is the one that can change roles, read every record and manage the subscription, so it is the account worth protecting most.

When 2FA is on, signing in asks for a code after the password. If you lose your phone, a recovery code gets you back in — store those somewhere other than the phone itself.

Recovering deleted records

Deleting in Academiq does not destroy immediately. Records move to a trash first:

  • Academic › Trash — years, terms, classes, sections, subjects and related records.
  • Staff › Staff Trash — teachers, staff and accountants.

An administrator can restore from either. This matters most for academic records: deleting a class or section outright would orphan every register and result attached to it.

The activity log

More › Activity Logs records significant actions taken in your institution — who did what, and when, including sign-in events. Use it when you need to establish what happened: who changed a mark, who deleted a record, who recorded a payment.

The log is visible to administrators. It is your record of your own school's activity.

How your data is kept separate

Every record in Academiq belongs to an institution, and a request is answered only with records belonging to the institution of the user making it. A user at another school cannot reach your students, staff, finances or documents — not by searching, not by guessing an address, and not by following a link somebody sent them.

This applies within your school too. Parents see their own children. Students see themselves. Teachers see the classes assigned to them. These are checked when each request is made, not merely hidden in the menu.

Uploaded files

Documents and photographs are held in private storage, not in a publicly served folder, and every download is authorised at the moment it is requested. See Certificates, ID cards and documents.

What your school is responsible for

Academiq secures the platform; the rest is down to how you run it:

  • Give people the narrowest role that lets them do their job — see Roles, permissions and portals.
  • Remove access promptly when someone leaves.
  • Do not share logins. A shared account makes the activity log useless, because it no longer identifies a person.
  • Keep more than one administrator.
  • Have a lawful basis for the personal data you record, particularly about children. The Privacy Policy sets out where that responsibility sits.

Reporting a problem

If you think you have found a security problem, email support@academiqedu.com rather than testing it further. The Terms of Service ask you not to probe the service without written permission, and a report gets it fixed faster.