Edunostics
Book demo

Security

Enterprise-grade security for every school.

Student data is among the most sensitive information a school holds. We built Edunostics from the ground up with security as a core requirement.

Contact security team

Encryption everywhere

AES-256 encryption at rest. TLS 1.3 for every connection. No data travels or sits unprotected at any layer of our stack.

Least-privilege access

Every user role has a precise, minimal access scope. Teachers see only their classes. Parents see only their children. No data leaks across accounts.

Full audit logging

Every action including score edits, report approvals, logins, and exports is logged with a timestamp and user identity. Nothing happens without a trace.

Redundant infrastructure

Edunostics runs on geographically distributed cloud infrastructure with automatic failover, load balancing, and a 99.9% uptime target.

Daily backups

Automated backups run every 24 hours across redundant storage locations. Recovery point objectives are measured in hours, not days.

Multi-factor authentication

Administrators can enforce MFA for all staff accounts. Session tokens are short-lived and invalidated on suspicious activity.

Penetration testing

We engage independent security firms to conduct regular penetration tests. Findings are remediated on a strict timeline before deployment.

Vulnerability disclosure

We maintain a responsible disclosure programme. If you discover a security issue, report it to it@edunostics.com for a rapid response.

Engineering practices

Security is baked into how we build.

Our security posture covers infrastructure, engineering practices, code review, and how we respond when something goes wrong.

All production code undergoes peer review before deployment

Dependency vulnerabilities are scanned on every commit

Critical patches are applied within 48 hours of disclosure

No student data is used in development or testing environments

Vendor and third-party access requires written authorisation

Security training is mandatory for all Edunostics employees

Incident response drills are conducted quarterly

Infrastructure access requires hardware security keys

Responsible disclosure

Found a vulnerability?

We take security reports seriously and commit to responding within 24 hours. We will never take legal action against researchers who disclose vulnerabilities in good faith.

Report a vulnerability