How would you design and implement a scalable, secure API for a student portal that handles high traffic and sensitive data, like grades and personal information? Walk us through the architecture, security measures, and performance optimization strategies you'd apply.