Enterprise-Grade Security for Education Data
Student records, financial data, and personal information demand the highest level of protection. ScolaOS is built with security at every layer - from infrastructure to application code.
Compliance & Certifications
Aligned with international security standards and regional data protection regulations.
ISO 27001 Ready
Our security controls and processes are aligned with ISO 27001 information security management standards, ensuring systematic protection of sensitive education data.
SOC 2 Aligned
ScolaOS follows SOC 2 Type II principles for security, availability, processing integrity, confidentiality, and privacy across all platform operations.
PDPA Aligned
Built to align with the Personal Data Protection Act and regional data-privacy regulations across the Southeast Asian jurisdictions where our institutions operate.
Encryption
Data is encrypted at every stage of its lifecycle - in transit, at rest, and in backups.
AES-256 at Rest
All data stored in our databases and file storage systems is encrypted using AES-256 encryption. Database backups, file uploads, and archived data are all encrypted before being written to disk.
TLS 1.3 in Transit
Every data transmission between clients and servers uses TLS 1.3 with strong cipher suites. API calls, file uploads, webhook deliveries, and inter-service communication are all encrypted.
Key Management
Encryption keys are managed through a dedicated key management service with automatic rotation schedules. Keys are never stored alongside the data they protect.
Access Control
Role-based access control ensuring every user sees only what they need to see and can do only what they are authorized to do.
7 User Types
Super Admin, School Admin, Branch Admin, Teacher, Staff, Student, and Parent - each with distinct base permissions and capabilities tailored to their role in the institution.
118 Granular Permissions
Fine-grained permission codes control access to every feature. Assign exact capabilities like "view attendance" or "manage fee structures" without granting unnecessary access.
Session Management
JWT-based authentication with database-tracked sessions, refresh token rotation, concurrent session limits, forced logout capabilities, and automatic timeout for inactive sessions.
Multi-Factor Authentication
TOTP-based MFA with backup codes for administrator accounts. Institutions can enforce MFA policies for specific user types to add an extra layer of protection.
Audit & Monitoring
Complete visibility into every action taken on the platform for compliance and security purposes.
Comprehensive Audit Logging
Every data modification, login attempt, permission change, and administrative action is recorded with the actor, timestamp, IP address, and detailed change payload.
Activity Tracking
Real-time activity feeds for administrators showing who accessed what, when, and from where. Exportable logs for compliance audits and incident investigation.
Anomaly Detection
Automated monitoring for suspicious patterns including unusual login locations, bulk data exports, rapid permission changes, and after-hours administrative actions.
Infrastructure Security
Multiple layers of infrastructure protection to keep the platform available and secure.
DDoS Protection
Multi-layer DDoS mitigation at the network and application layers. Rate limiting, traffic analysis, and automatic blocking of malicious request patterns.
Web Application Firewall
WAF rules protecting against OWASP Top 10 vulnerabilities including SQL injection, XSS, CSRF, and request forgery. Custom rules for education-specific attack vectors.
Automated Backups
Automated database backups every 6 hours with point-in-time recovery capability. Backups are encrypted, stored in geographically separate regions, and tested regularly.
Disaster Recovery
RPO of less than 1 hour and RTO of less than 4 hours. Documented and tested disaster recovery procedures with automated failover to standby infrastructure.
Questions About Security?
Our security team is available to discuss compliance requirements, answer technical questions, and provide detailed security documentation.
