What protects your Skyward login
Skylight has to sign in to Skyward as you, so it holds your login. Everything here comes from keeping as little as possible, and making what is kept useless to anyone who only has the database.
Your password is the key, and the server doesn't keep it
When you sign in, your password is stretched into a key that never leaves the request. That key unwraps the data key, and the data key opens your encrypted Skyward login and grades. Sign out and the server is back to holding ciphertext.
Envelope encryption
AES-256-GCM under a data key generated for you alone. That key is itself wrapped by a key that comes from your Skylight password, so the stored ciphertext is useless without you.
PBKDF2-SHA256, 600,000 iterations
Your Skylight password is stretched 600,000 times before it becomes a key, which is what makes guessing it expensive.
Sealed session cookies
Sessions are HttpOnly and SameSite, and the cookie itself is encrypted. JavaScript cannot read it and another site cannot borrow it.
Rate limiting
Sign-in, sign-up, account changes and the sync that takes credentials are all rate limited, so Skylight cannot be turned into a password-guessing proxy aimed at the school.
Strict CSP with nonces, and HSTS
Only Skylight's own scripts can run, each page load marks them with a fresh nonce, and browsers are told to reach the site over HTTPS only.
Encrypted push
Push messages are encrypted to your device, so the service relaying them cannot read them.
The three levels
You pick one in Settings and can change it whenever you like. Stepping back down deletes what was stored.
| Level | Account | Skyward login | Grades | Background checks | In short |
|---|---|---|---|---|---|
| Guest | None | Never stored | This browser tab only | No | Nothing at all is saved on the server. |
| Saved & encrypted | Yes | Encrypted | Encrypted | No | Readable only while you are signed in. |
| Background alerts | Yes | Encrypted, plus a server-key copy | Encrypted, plus a server-key copy | Every 15 min | Opt-in. The server can open this on its own. See the warning below. |
Background alerts are the weaker option, on purpose. To check for new grades while you are asleep, the server has to open your vault without you, so a second copy of your data key is locked with a server secret. Anyone who got hold of both the database and that secret could read the Skyward login. That is weaker than Saved & encrypted on its own, which is why the setting starts off and says so before you switch it on.
What none of this covers
Your Skyward password is only ever used to sign in to Skyward. In guest mode it is never stored. With an account it is stored only as ciphertext that your Skylight password opens.
Skylight cannot be safer than Skyward. Anyone who knows a student's Skyward login can already read everything Skylight shows by signing in to Skyward directly, and could use it to reset that student's Skylight password. Guard the school login first.
A security page is not proof. Skylight is a small independent project, it has not been audited, and it is not affiliated with Skyward, Qmlativ or Plano ISD. If you would rather no copy of your login existed anywhere, use guest mode. It needs no account and saves nothing, and that is what it is there for.
Pick the level you are comfortable with
Guest mode saves nothing at all, and you can change your mind later without losing your account.