Role access, encryption, and audit trails for school records.

Student data is among the most sensitive information a school holds. Edunostics treats security as a core requirement, not an add-on.

Encryption everywhere

AES-256 encryption at rest. TLS 1.3 for every connection. Data is protected in transit and at rest.

Least-privilege access

Each role has a minimal scope. Teachers see their classes. Parents see their children. Accounts do not share data sideways.

Publish control

Score sheets and report cards stay unpublished until review. Schools can test a class report, then publish or unpublish a card.

Full audit logging

Score edits, report approvals, logins, and exports are logged with timestamp and user identity.

Redundant infrastructure

Geographically distributed cloud infrastructure with automatic failover, load balancing, and a 99.9% uptime target.

Daily backups

Automated backups every 24 hours across redundant storage. Recovery objectives are measured in hours.

Multi-factor authentication

Administrators can enforce MFA for staff accounts. Session tokens are short-lived and invalidated on suspicious activity.

Penetration testing

Independent firms run regular penetration tests. Findings are remediated on a fixed timeline before deployment.

Vulnerability disclosure

Report issues to it@edunostics.com. We maintain a responsible disclosure programme with rapid response.

How we build and operate

Practices across infrastructure, engineering, review, and incident response.

Peer reviewAll production code undergoes peer review before deployment.
Dependency scanningDependency vulnerabilities are scanned on every commit.
Critical patchesCritical patches are applied within 48 hours of disclosure.
No prod data in testNo student data is used in development or testing environments.
Vendor accessVendor and third-party access requires written authorisation.
Staff trainingSecurity training is mandatory for all Edunostics employees.
Incident drillsIncident response drills are conducted quarterly.
Hardware keysInfrastructure access requires hardware security keys.

Found a vulnerability?

We respond to good-faith reports within 24 hours. Researchers who disclose responsibly will not face legal action from us.

Report a vulnerability