Security

What protects your Skyward login

Skylight has to sign in to Skyward as you, so it holds your login. Everything here comes from keeping as little as possible, and making what is kept useless to anyone who only has the database.

600,000 PBKDF2-SHA256 iterations Before your Skylight password becomes a key.
256-bit AES-GCM encryption Envelope encryption with a data key generated for you alone.
0 Extra personal data You sign in with a Skylight username. No email address, and nothing else collected.
1 Button to delete it all Delete everything removes every row Skylight holds about you.
The core idea

Your password is the key, and the server doesn't keep it

When you sign in, your password is stretched into a key that never leaves the request. That key unwraps the data key, and the data key opens your encrypted Skyward login and grades. Sign out and the server is back to holding ciphertext.

Envelope encryption

AES-256-GCM under a data key generated for you alone. That key is itself wrapped by a key that comes from your Skylight password, so the stored ciphertext is useless without you.

PBKDF2-SHA256, 600,000 iterations

Your Skylight password is stretched 600,000 times before it becomes a key, which is what makes guessing it expensive.

Sealed session cookies

Sessions are HttpOnly and SameSite, and the cookie itself is encrypted. JavaScript cannot read it and another site cannot borrow it.

Rate limiting

Sign-in, sign-up, account changes and the sync that takes credentials are all rate limited, so Skylight cannot be turned into a password-guessing proxy aimed at the school.

Strict CSP with nonces, and HSTS

Only Skylight's own scripts can run, each page load marks them with a fresh nonce, and browsers are told to reach the site over HTTPS only.

Encrypted push

Push messages are encrypted to your device, so the service relaying them cannot read them.

Storage tiers

The three levels

You pick one in Settings and can change it whenever you like. Stepping back down deletes what was stored.

Skylight's three storage levels and what each one keeps
LevelAccountSkyward loginGradesBackground checksIn short
GuestNoneNever storedThis browser tab onlyNoNothing at all is saved on the server.
Saved & encryptedYesEncryptedEncryptedNoReadable only while you are signed in.
Background alertsYesEncrypted, plus a server-key copyEncrypted, plus a server-key copyEvery 15 minOpt-in. The server can open this on its own. See the warning below.

Background alerts are the weaker option, on purpose. To check for new grades while you are asleep, the server has to open your vault without you, so a second copy of your data key is locked with a server secret. Anyone who got hold of both the database and that secret could read the Skyward login. That is weaker than Saved & encrypted on its own, which is why the setting starts off and says so before you switch it on.

Limits

What none of this covers

Your Skyward password is only ever used to sign in to Skyward. In guest mode it is never stored. With an account it is stored only as ciphertext that your Skylight password opens.

Skylight cannot be safer than Skyward. Anyone who knows a student's Skyward login can already read everything Skylight shows by signing in to Skyward directly, and could use it to reset that student's Skylight password. Guard the school login first.

A security page is not proof. Skylight is a small independent project, it has not been audited, and it is not affiliated with Skyward, Qmlativ or Plano ISD. If you would rather no copy of your login existed anywhere, use guest mode. It needs no account and saves nothing, and that is what it is there for.

Pick the level you are comfortable with

Guest mode saves nothing at all, and you can change your mind later without losing your account.