Security
Student data is among the most sensitive information a school holds. We built Edunostics from the ground up with security as a core requirement.
Contact security teamAES-256 encryption at rest. TLS 1.3 for every connection. No data travels or sits unprotected at any layer of our stack.
Every user role has a precise, minimal access scope. Teachers see only their classes. Parents see only their children. No data leaks across accounts.
Every action including score edits, report approvals, logins, and exports is logged with a timestamp and user identity. Nothing happens without a trace.
Edunostics runs on geographically distributed cloud infrastructure with automatic failover, load balancing, and a 99.9% uptime target.
Automated backups run every 24 hours across redundant storage locations. Recovery point objectives are measured in hours, not days.
Administrators can enforce MFA for all staff accounts. Session tokens are short-lived and invalidated on suspicious activity.
We engage independent security firms to conduct regular penetration tests. Findings are remediated on a strict timeline before deployment.
We maintain a responsible disclosure programme. If you discover a security issue, report it to it@edunostics.com for a rapid response.
Engineering practices
Our security posture covers infrastructure, engineering practices, code review, and how we respond when something goes wrong.
All production code undergoes peer review before deployment
Dependency vulnerabilities are scanned on every commit
Critical patches are applied within 48 hours of disclosure
No student data is used in development or testing environments
Vendor and third-party access requires written authorisation
Security training is mandatory for all Edunostics employees
Incident response drills are conducted quarterly
Infrastructure access requires hardware security keys
Responsible disclosure
We take security reports seriously and commit to responding within 24 hours. We will never take legal action against researchers who disclose vulnerabilities in good faith.
Report a vulnerability