Security

Built around trust.

CSS is designed with controlled access, short-lived enrollment, and biometric templates that never leave protected storage.

Authentication

Admin pages require a signed session. Terminals authenticate with a unique token.

Enrollment sessions

Enrollment links are one-time, hashed at rest, and expire after a short window.

Token expiry

QR enrollment sessions time out so unused links cannot stay open indefinitely.

Terminal access

A revoked terminal cannot record attendance, even if someone still has an old URL.

Biometric abstraction

Matching runs through a provider interface so camera capture can later be replaced by hardware.

Data protection

Fingerprint templates are stored as protected data and are never shown in the interface.

Notifications

Every parent message is recorded, so schools keep an auditable history of what was sent and when.