Security & your data
Plain answers, no jargon, no exaggeration. We will never tell you any system is "hack-proof" — nobody honest can. This page sets out, in clear terms, what we actually do to protect your school's data.
Our promise on honesty
No system is unbreakable, and we will never claim ours is. What we commit to instead is concrete and verifiable:
- Real encryption — in transit and at rest.
- Real isolation — enforced by the database itself, not merely by the application.
- Real backups — kept encrypted and periodically test-restored, because a backup you have never restored is a hope, not a plan.
- Prompt, honest notification — if anything ever goes wrong, we will tell your school clearly and quickly, as India's Digital Personal Data Protection (DPDP) Act requires, and as we would want if it were our own children's data.
We would rather earn your trust with candour than risk it with marketing.
How your data is protected
Encrypted in transit and at rest. All traffic between your devices and our servers is protected with industry-standard HTTPS/TLS encryption, and stored data is encrypted on disk by our cloud infrastructure.
One school's data is walled off from every other school. Isolation is enforced inside the database itself, not just in the app. Every request is checked against your school's membership before a single record is returned, so a fault in one screen cannot expose another school's data — the database simply will not serve it.
Sensitive proofs get extra protection. Attendance photo-proofs are encrypted with AES-256 before they are stored and are readable only within your own school. When face check-in is released, biometric data will be handled under per-school keys, designed so that only your school's own administrators — not our staff — can read it. Until a feature genuinely works, the app says so plainly; we do not simulate capabilities.
Backed up and recoverable. We keep regular, encrypted backups and maintain the ability to restore to a recent point in time. We periodically test the restore process, so recovery is a practised procedure rather than an untested assumption.
Nothing is public unless you publish it. Optional features such as the public Merit Board display information only when your school explicitly opts in and confirms it has the necessary consent, and you can withdraw at any time. Everything else stays private to your school.
Hosted in-region. Your data is hosted with our cloud provider in the Asia-Pacific region (India). We confirm the exact hosting region in your onboarding documentation and in our Privacy Policy.
Your data belongs to your school
Under the DPDP Act, your school is the data fiduciary and we act as your processor — we handle personal data only on your instructions. You can export your records at any time, free of charge, in standard formats. If you leave, we return or delete your data on your instruction, as set out in our Privacy Policy. We do not sell your data, and we do not use student data to train AI models.
Who processes data on our behalf (sub-processors)
We keep this list short and purposeful. Each provider below is bound by contract to use your data only to deliver the service described.
| Service | Purpose | Data involved |
|---|---|---|
| Managed cloud database, authentication & hosting | Securely stores application data and enforces per-school isolation | Account, institutional and student records; uploaded files |
| Cashfree Payments | Processes subscription payments | Billing/payment details (handled directly by Cashfree) and transaction metadata |
| AiEng — AI & OCR processing | Powers the OCR and AI-assistant features you choose to use | Only the content you submit to an AI feature (e.g. a mark-sheet image or a prompt) |
| Email / communications provider | Sends transactional and support email | Email address and message content |
| Content-delivery / infrastructure provider | Serves the application quickly and reliably | Technical request data (e.g. IP address, device type) |
We use the brand AiEng for our AI capabilities and do not disclose the underlying AI technology providers. Content you submit to an AI feature is processed only to produce your result — it is never used to train third-party models.
For reviewers and IT staff
Our approach favours defence in depth over slogans: database-enforced tenant isolation, encryption in transit and at rest, least-privilege access, metered and auditable AI usage, and a documented incident-notification process aligned to the DPDP Act. We are glad to answer specific security questions during onboarding.
Questions? Ask us anything about this page — including any part still marked "to confirm".
AiduEdSuite
Open app →