Skip to content

Enterprise-Grade Security for Education Data

Student records, financial data, and personal information demand the highest level of protection. ScolaOS is built with security at every layer - from infrastructure to application code.

Compliance & Certifications

Aligned with international security standards and regional data protection regulations.

ISO 27001 Ready

Our security controls and processes are aligned with ISO 27001 information security management standards, ensuring systematic protection of sensitive education data.

SOC 2 Aligned

ScolaOS follows SOC 2 Type II principles for security, availability, processing integrity, confidentiality, and privacy across all platform operations.

PDPA Aligned

Built to align with the Personal Data Protection Act and regional data-privacy regulations across the Southeast Asian jurisdictions where our institutions operate.

Encryption

Data is encrypted at every stage of its lifecycle - in transit, at rest, and in backups.

AES-256 at Rest

All data stored in our databases and file storage systems is encrypted using AES-256 encryption. Database backups, file uploads, and archived data are all encrypted before being written to disk.

TLS 1.3 in Transit

Every data transmission between clients and servers uses TLS 1.3 with strong cipher suites. API calls, file uploads, webhook deliveries, and inter-service communication are all encrypted.

Key Management

Encryption keys are managed through a dedicated key management service with automatic rotation schedules. Keys are never stored alongside the data they protect.

Access Control

Role-based access control ensuring every user sees only what they need to see and can do only what they are authorized to do.

7 User Types

Super Admin, School Admin, Branch Admin, Teacher, Staff, Student, and Parent - each with distinct base permissions and capabilities tailored to their role in the institution.

118 Granular Permissions

Fine-grained permission codes control access to every feature. Assign exact capabilities like "view attendance" or "manage fee structures" without granting unnecessary access.

Session Management

JWT-based authentication with database-tracked sessions, refresh token rotation, concurrent session limits, forced logout capabilities, and automatic timeout for inactive sessions.

Multi-Factor Authentication

TOTP-based MFA with backup codes for administrator accounts. Institutions can enforce MFA policies for specific user types to add an extra layer of protection.

Audit & Monitoring

Complete visibility into every action taken on the platform for compliance and security purposes.

Comprehensive Audit Logging

Every data modification, login attempt, permission change, and administrative action is recorded with the actor, timestamp, IP address, and detailed change payload.

Activity Tracking

Real-time activity feeds for administrators showing who accessed what, when, and from where. Exportable logs for compliance audits and incident investigation.

Anomaly Detection

Automated monitoring for suspicious patterns including unusual login locations, bulk data exports, rapid permission changes, and after-hours administrative actions.

Infrastructure Security

Multiple layers of infrastructure protection to keep the platform available and secure.

DDoS Protection

Multi-layer DDoS mitigation at the network and application layers. Rate limiting, traffic analysis, and automatic blocking of malicious request patterns.

Web Application Firewall

WAF rules protecting against OWASP Top 10 vulnerabilities including SQL injection, XSS, CSRF, and request forgery. Custom rules for education-specific attack vectors.

Automated Backups

Automated database backups every 6 hours with point-in-time recovery capability. Backups are encrypted, stored in geographically separate regions, and tested regularly.

Disaster Recovery

RPO of less than 1 hour and RTO of less than 4 hours. Documented and tested disaster recovery procedures with automated failover to standby infrastructure.

Questions About Security?

Our security team is available to discuss compliance requirements, answer technical questions, and provide detailed security documentation.