Your data, separated and protected.
A plain account of how Folio isolates each institution, enforces access at the database, and keeps a record of what changes. No jargon, no hand-waving.
View live system statusIsolation per institution
Every institution runs on its own subdomain, and its records are scoped to its own institution at every query. A student, a course, a grade belongs to one institution and is only ever read in that context.
Row-level security, at the database
Access is enforced in Postgres itself with row-level security, not only in the interface. A request made as a signed-in person cannot read someone else’s protected rows, because the database refuses to return them.
Scoped sessions & access
Sessions are scoped to your institution’s domain. Roles separate duties: administrators, registrars and staff each see only what their role permits, and platform-level access is limited and deliberate.
An audit trail
Administrative changes are recorded: who changed what, and when. The record is there for your own review and for the questions procurement and compliance teams ask.
We don’t mine your work
Your institution’s content is yours. Folio’s AI answers from the sources you give it; we do not sell your data, and we do not train models on your students’ work.
Compliance posture
Folio is built to a GDPR-aligned standard, and a Data Processing Agreement is available on request. Single sign-on over OpenID Connect or SAML 2.0 is available for institution tenants. Regional data residency work is in progress; EU hosting is planned but not yet live. We do not currently publish a commercial SLA or third-party compliance certification; ask us for the technical details your review requires.
Why isolation matters
An LMS holds an institution’s whole record: rosters, grades, messages. When isolation has a weak seam, one exploited sign-up flow can expose far more than a single course. Folio checks isolation in two layers: row-level security in the database refuses rows outside a signed-in person’s scope, and the server tasks that need wider access scope each query to one institution. Ask for a walkthrough and your security team gets the technical detail.
