Security Statement

How KAMAR ensures your data remains secure.


The security of your data is the highest priority to us and we are continually reviewing this in terms of KAMAR, school.kiwi and our own network and procedures.

KAMAR has put in place systems to manage risks related to the security of data, including best practices and principles enshrined in the ISO/IEC 27001 International Standard.

  • Confidentiality: Only the right people can access the information held.
  • Information integrity: Data is reliably stored and not erased or damaged.
  • Availability of data: Clients can access the information whenever it is necessary so that business purposes and customer expectations are satisfied.


Additionally, we are in the processes of completing the ST4S (Safer Technologies for Schools) certification. We are currently waiting for ST4S to complete their review process and we are expecting to achieve this by the end of 2026.


Client Access

The biggest risk to your data is end users. Compromised logon details being the most common event.

KAMAR enforces 2FA (Two Factor Authentication) for all users accessing KAMAR, either via email or OTP (One Time Passcode). We recommend the use of OTP and that this is biometrical protected (MFA / Multi-Factor Authentication).


Audit Logging

User navigation and record modification is logged, against the logged on user, the record modified and globally.

Logs can be viewed, either within KAMAR or on the server itself.


Backend Technologies

KAMAR is built on Claris FileMaker. Claris is a subsidiary of Apple Inc. and as part of every release, FileMaker is subjected to Apple's security review process.

Apple (and thus Claris / FileMaker) maintains certifications in compliance with the ISO/IEC 27001 and ISO/IEC 27018.

Staying up to date with the latest version of FileMaker ensures newly identified threats are patched.


Data Encryption in Transit / at Rest

FileMaker uses TLS 1.2 or higher to ensure all data is transmitted security between server and client - regardless if using the desktop application or via a web browser.

Direct access to the physical files should always be avoided, however FileMaker ensures data is never stored in plain text, including backups. This includes enabling EAR (Encryption at Rest) using AES256 encryption.


Internal Reviews

Whenever a change is made that potentially affects the security of your data, this is first reviewed by another developer. Next, it is passed onto our Quality Assurance team for testing and documentation - all this happens before beta testing and finally public release.


External Reviews

KAMAR performs a third party security audit on a regular basis. Additionally, regular automated PEN testing tools are used.

Past audits have focused on:

  • KAMAR Student Management System
  • school.kiwi Parent/Student Web portal
  • internal network, policies and procedures.


Hosted Schools

KAMAR can be cloud hosted or self-hosted.

When a school hosts KAMAR in our cloud hosting environment, we take on the responsibility of ensuring your environment is backed up and up to date. Updates are first tested before being rolled out to all hosted schools.