PASSWORDLESS BY DESIGN

Most people never geta password at all.

One tap in. No password to lose.

Teachers, parents and students sign in with the Google or Apple account already on their phone. Nothing for your office to hand out, nothing to reset, nothing that can be forwarded — because for most people SMS never creates a password at all. A school holds the most sensitive record most families will ever have, so we treat that as a duty of care, not a feature.

0
passwords we ever send to a parent
2 min
for a family to set themselves up
1
account per person — never a duplicate
WHAT A PARENT ACTUALLY SEES
Continue with GoogleContinue with AppleContinue with email

No password is emailed, texted, or printed — ever.

02Getting in

Everyone signs in with an account they already have.

Teachers, parents and students use their existing Google or Apple account — the same one on their phone. There is nothing for your office to hand out, and no list of passwords for anyone to keep track of.

IN PRACTICEA teacher joins in September. She taps “Continue with Google”, uses the account she already has, and is teaching by lunchtime — without anyone writing a temporary password on a sticky note.

Continue with Google

Sign in with Google

Tap the Google button, pick the account, done. SMS never sees the person’s Google password — Google confirms who they are and tells us.

How it works

The app obtains an identity token from Google on the device itself and posts it to SMS, which verifies the signature and reads the claims. SMS never sees a Google password, and never asks for one.

  • 01The account's email must be marked verified by Google. An unverified identity is refused outright, before any account is created or touched.
  • 02Access tokens are not stored. SMS keeps the verified identity, not a key to the person's Google account — so a breach here does not become a breach there.
  • 03If the address already belongs to an SMS account, the Google identity is linked to it. A second account for the same human being is never created.
  • 04With the person's permission, the phone number on their Google profile can pre-fill contact details. Nothing else from the profile is used.
Continue with Apple

Sign in with Apple

The same one tap on an iPhone, using Face ID or a fingerprint. Best for parents, who are usually signing in from their own phone.

How it works

The same client-side flow as Google, through an Apple Services ID. Aimed mainly at parents and guardians signing in from personal iPhones rather than school-issued accounts.

  • 01Face ID or Touch ID satisfies Apple's own check on the device, so a parent gets strong authentication without installing an authenticator app.
  • 02Hide My Email is supported. A family can withhold their real address and still receive every notification through Apple's private relay.
  • 03Apple's verified-email claim is enforced exactly as Google's is — the rule lives in one shared adapter, so neither provider can become the weaker door.
  • 04A guardian can hold both an Apple and a Google identity on one record, so changing phone or Apple ID never means losing history.
Continue with email

Email and password

For anyone with neither. They set their own password, and confirm their email address before the account works.

How it works

The fallback where neither provider suits. Email is the only login identifier SMS accepts, and an address must be confirmed before the account is usable.

  • 01Password validators apply on entry: a minimum length, a check against the most common passwords, rejection of all-numeric passwords, and rejection of passwords that resemble the person's own name or email.
  • 02Passwords are stored salted and hashed, never in plain text, and cannot be read back by SMS staff or by your own administrators.
  • 03Email confirmation is mandatory before an account can be used, and confirmation links expire after seven days.
  • 04Sign-in by one-time code is available, so someone who has forgotten a password can get in without a new one being issued to them.

However someone signs in, they land on the one account your school already has for them. Signing in a new way adds a key to the same door — it never creates a second door.

The technical detail, for your IT lead

SMS uses Google and Apple to confirm who someone is. It does not require your school to run Google Workspace, join anything, or own a corporate domain — a personal account works fine, and SMS simply matches the confirmed identity to the record your school already holds.

WHAT SIGNING IN CAN NEVER DO

The dangerous moment in any school system is when an outsider’s login meets an insider’s permissions. These four rules are written once and apply to every way of signing in, so no single login button can become the weak one.

It cannot make anyone an administrator

Signing in with Google or Apple never gives anyone extra powers, and never changes what an existing account is allowed to do. Only someone at your school can promote someone — never Google, never Apple, never us.

It cannot create a second you

If the email already belongs to someone in your school, the new sign-in method is attached to that same person. You will not end up with two half-filled records for one teacher.

It cannot reopen a closed door

When someone leaves, they are out — and no sign-in method lets them back in. The message they see is deliberately vague, so a stranger cannot use the login screen to work out who used to work at your school.

It cannot start you above the floor

Anyone who signs up on their own starts as an applicant: they can submit an application and see nothing else. Every step above that is given deliberately, by a named person at your school.

03Parent onboarding

A parent proves who they are, then sets their own sign-in.

Nothing is emailed. Nothing is posted. Nothing to forward.

The weakest link in most school systems is not the login screen — it is the way passwords reach families in the first place. Passwords printed on slips and sent home in a schoolbag. Temporary logins emailed to an address the school last confirmed four years ago. Reset links pasted into a class WhatsApp group by a parent trying to be helpful.

Every one of those creates something that can be passed on — and that works for whoever ends up holding it. SMS onboarding never creates one. A parent proves who they are using something they already have and something only they know, then sets up their own sign-in on their own device. At no point does a working password travel to them.

WHAT NEVER HAPPENS
  • No password is emailed, texted, or printed
  • No magic link that works for whoever opens it
  • No temporary password to change later
  • No shared family login passed between parents
HOW A PARENT IS PROVEN
SOMETHING THEY HAVE

The child's ID card

The barcode on the back of the card already in the family's possession. Parents are never issued a card of their own, and one card covers every sibling at the school.

SOMETHING THEY KNOW

The CNIC on record

Matched against the identity number the school already holds for that guardian — or, where none is held, the mobile number registered with the office. A found card on its own gets nobody in.

Two independent factors, verified before any account exists to attack.

  1. 01

    Install the school app

    From the App Store or Google Play, or by pointing a phone camera at the code on the school's handout.

  2. 02

    Tap “Sign up with ID card” — not log in

    There is deliberately no password to try yet. Nothing exists at this point that a phishing page could ask for or an attacker could guess.

    SECURITY
  3. 03

    Scan the barcode on the back of the card

    The camera reads it in the frame with no button to press. No camera, or poor light? Upload a photo, or type the code printed beneath the barcode.

  4. 04

    Choose your own name

    The app lists only the people already linked to that student — Father, Mother, Guardian. It never offers a name the school has not already recorded for that family.

    SECURITY
  5. 05

    Confirm it is really you

    Enter the CNIC number the school holds for you, or the mobile number registered with the office. This is the step that separates a parent from someone who merely found a card.

    SECURITY
  6. 06

    Choose how you will sign in

    Continue with Google, Continue with Apple, or set an email and password of your own. Whatever they choose is set up by them, on their own phone — it is never sent to them.

    SECURITY

And they are in.

No email to wait for, no link to click, no password to keep somewhere safe. The moment step six finishes the parent is signed in and looking at their child's attendance, homework, results and fee status.

SETUP TIME · ABOUT TWO MINUTES
WHEN SETUP STOPS — AND WHY THAT IS THE POINT

Account already set up

Someone — usually the other parent — has already claimed this guardian identity. A second person cannot silently take it over. The office resolves it, with a human in the loop.

Contact the school office

The school holds no CNIC or mobile number for this guardian, so the second factor cannot be checked. Rather than waving them through, setup stops and identity is proven in person. One visit fixes it permanently.

Card not recognised

The scan failed, or the card does not belong to this school. The parent can retry in better light or type the code by hand — but a card SMS does not recognise never becomes a way in.

The same proof on a computer

Families without a suitable phone complete the identical flow in a browser — holding the card up to a webcam or uploading a photo of it. The route changes; the two factors do not.

04Administrators

Administrator accounts need a second factor.

Being an admin is a responsibility, not a convenience.

An administrator account can see every child in the school. Their home address. Which parent is permitted to collect them. Who owes fees, who has been absent every Monday since September. That is not company data in the abstract — it is a list of children and where to find them.

Almost every school breach we have read about began with one over-privileged account and one reused password. Not a sophisticated attack on infrastructure — a phished administrator on a Tuesday afternoon. SMS gives every administrator the tools to make that attack fail, and asks them plainly to turn them on.

SHOWN WHEN AN ADMINISTRATOR ROLE IS GRANTED

The administrator's undertaking

Before taking up the role, a new administrator reads and acknowledges five statements. It takes about forty seconds. It is not a legal instrument — it is a moment of deliberate attention before someone is handed the keys.

  1. 01

    I can see personal information about every child in this school, including where they live and who may collect them.

  2. 02

    I will use that access only for my work, and only when the work requires it.

  3. 03

    I will enrol a second factor, and I will not share my account, my device, or that factor with anyone — including colleagues I trust and senior staff who ask.

  4. 04

    I understand that the changes I make are recorded against my name, and that this is a protection for me as much as a check on me.

  5. 05

    If I believe my account has been compromised, I will report it the same day, and I will not be penalised for reporting it.

ACKNOWLEDGED · RECORDED AGAINST THE ROLE GRANT

A second factor is simply a second check after the password — something the person has, as well as something they know. Even if a password is stolen, it is not enough on its own.

SECOND FACTORS AVAILABLE TODAY
01

Your face or fingerprintPREFERRED

Also called a passkey — Face ID, Touch ID, Windows Hello

Strongest

The safest option, and the easiest. A fake login page cannot steal it, because it only works on the real SMS site — even a convincing copy gets nothing. This is what we ask administrators to use.

02

A 6-digit code on your phone

From a free app like Google Authenticator or 1Password

Strong

Works on any phone and most people have used one before. Slightly weaker, because a convincing fake site can trick someone into typing the code into it.

03

Printed backup codes

For the morning you lose your phone

Recovery only

Keep them somewhere safe at home. Each one works once, then stops. A way back in — not a way to sign in every day.

A code by text message

We deliberately do not offer this

Not supported

Someone can persuade a phone company to move a number to their own SIM, and a text is readable on a locked screen without unlocking it. We would rather explain this choice than deal with what it lets in.

WHAT PROTECTS AN ADMINISTRATOR ACCOUNT TODAY
LIVE

Face or fingerprint, ready today

An administrator can switch to signing in with their face or fingerprint today — nothing needs enabling first. It takes under a minute and it is the single biggest improvement they can make, because a fake login page cannot copy it.

LIVE

See every device, sign any of them out

Active sessions are tracked with device and last activity, and can be ended remotely. An administrator who suspects something can close every other session themselves, immediately, without calling anyone.

LIVE

More than one way into the same account

Google, Apple and a password can all work for the same administrator. Losing one does not become a panicked reset — which is usually the moment a password ends up being sent somewhere it should not be.

LIVE

Google and Apple cannot promote anyone

Signing in never changes what an account is allowed to do. Even if someone completely takes over a teacher's Google account, they get that teacher's access — never an administrator's.

PLANNED

Required, not just encouraged

Planned: an administrator would not be able to use the role at all until a second check is set up — so the protection comes with the job, rather than depending on each person remembering.

PLANNED

Asked again before the risky actions

Planned: asking for the second check again at the moment someone exports a whole year group, changes another person's access, or deletes in bulk — even if they signed in an hour ago.

Items marked LIVE work today. Items marked PLANNED are things we intend to build — written down here so you can hold us to them. Ask where each one stands at your walkthrough.

05Least privilege

Everyone sees exactly their part of the school.

Access follows the job, through named roles assembled from individual capabilities rather than broad switches. Nothing is granted “just in case”, because the widest permission set is what an attacker inherits.

Default access by role across student records, class data, whole-school data, finance and settings
RoleOwn recordClass dataWhole schoolFinanceSettings
Applicantownnonenonenonenone
Studentfullownnonenonenone
Parent / guardianchildrenchildrennoneown feesnone
Teacherfullassignednonenonenone
Finance officerfullnonereadfullnone
Administratorfullfullfullfullfull

Roles are configurable per school; this is an illustrative default. Every role, role assignment and capability change is itself recorded in the audit log.

06Accountability

Who changed what, kept permanently.

The records that matter keep their history.

SMS keeps a permanent list of who changed what, and when. If a grade, a fee or someone’s permissions change, the record shows which member of staff did it — which protects your staff as much as it checks them.

What exactly is recorded

Audit logging is deliberately narrow rather than exhaustive. Every change to an identity, a role, a student, an employee or a finance record is captured against the person who made it — while high-churn operational traffic such as attendance punches and notification deliveries is kept out, so the log stays something a human can actually read.

  • Identity and permission changes are tracked: accounts, email addresses, roles, role assignments and the capabilities behind them.
  • Student, employee, person, campus and fee-chart records are tracked, because a silent edit to any of them changes what the school believes to be true.
  • Finance is covered twice over — row-level changes to write-offs, refunds, credit notes and period locks, alongside a separate record of the financial decisions themselves.
  • Gap-free numbering is enforced on invoices, challans and receipts, so “why is there no receipt 1043?” always has an answer.

Today the log records changes, not views. Read-access logging on student records is something we would rather build properly than claim early.

AUDIT LOG · EXCERPT
  • 08:41A. Rahman · AdminRole assignedS. Amara → Head of Year
  • 08:44A. Rahman · AdminStudent record updatedHassan Raza · 8-B
  • 09:02M. Iqbal · FinanceWrite-off createdInvoice 2209 · fee reduced
  • 09:15SystemSign-in refused — email not verifiedunknown · Google
07The data itself

Your data is encrypted, separated, and deleted on schedule.

Held carefully, and no longer than needed.

The short version: your data is scrambled on the way in and out, kept apart from other schools, backed up, and never held longer than you need it.

Travelling over the internet
Everything sent between the app and SMS is scrambled on the way, so it cannot be read if intercepted — the same protection your bank uses.
One campus cannot see another
Staff see the campus they belong to. A second or third campus does not quietly become visible to everyone.
Nobody can read a password
Passwords are stored scrambled in a way that cannot be reversed. Not by us, not by your administrators, not by anyone who stole the database.
We hold no keys to Google or Apple
SMS keeps only the confirmation of who someone is — never a key to their Google or Apple account. A problem here cannot become a problem there.
You can see where you are signed in
Every phone and computer currently signed in is listed, with when it was last used. Any of them can be signed out remotely — useful the day a phone goes missing.
Uploaded files
Certificates, photographs and documents are stored apart from the main records, and every request for one is checked against what that person is allowed to see.
Copies, in case of disaster
Backups are taken on a schedule agreed with you. Ask us how far back they go and when we last practised restoring one — we will give you a real answer, not a slogan.
Where your data physically lives
Decided by where your system is set up, and confirmed with you in writing before you start.

Where this page cannot state a control precisely, it says so rather than reaching for a reassuring phrase. Bring your questions to the walkthrough and we will answer them against the code.

08If something goes wrong

How to report a vulnerability.

Tell us, and we will tell you.

No security programme is perfect, and a page like this is worth very little without a way to report what it missed.

Reporting a vulnerability

Send findings to security@sms.example. We acknowledge within one working day, keep you updated while we fix it, and will credit you publicly unless you would rather we didn't. We do not threaten researchers who act in good faith.

security@sms.example

If your school is affected

You are told directly, in plain language, with what we know and what we do not yet know — not a press release. We help you meet your own obligations to families rather than leaving you to work them out.

Ask about the incident policy

Bring your IT lead to the walkthrough.

We would rather answer the hard questions early. Send us your security questionnaire before the call and we will come with it filled in — including the parts still on the roadmap.