Skip to main content

Home/Security at Edutris, How We Protect School Data

Trust & security

How Edutris protects your school's data

A school's data (students, families, fees, health records) is among the most sensitive information any organisation holds. This page describes, specifically and without marketing gloss, the controls Edutris uses to protect it. If a control isn't listed here, we don't claim it.

At a glance

ItemDetail
Controls we operateSSL/TLS in transit, role-based access across seven portals, per-school data isolation, activity audit logs, automated rotated backups, server-side validation
Legal frameDesigned for the DPDP Act 2023: the school directs how its students’ data is used, and that data runs the school, never advertising
CertificationsNone claimed. Edutris does not hold ISO 27001 or SOC 2, and shows no badge it has not earned
UptimeAn internal target with always-on health monitoring: deliberately a target, not a contractual SLA
SupportReal people who know Indian school operations, reached through the contact page. Deliberately no published hours or response-time commitment — see the note in this file
If you leaveThe school owns its data, and Edutris supports exporting your records: ask for the specifics during evaluation
Book a demo →See pricing

30-day guided pilot · No credit card

What it looks like

Edutris user management screen listing staff accounts with name and email, a role badge of school head or teacher, employee id, last login date, an active toggle and a reset password action
Every staff account with its role, employee id and last login: switch access off, or reset one password, without touching any other account.
Edutris audit log with eleven recorded actions, each showing when it happened, who did it and in what role, the operation: collect, approve, waitlist, apply or publish, the record and action it touched, and the change recorded
Every recorded action carries who did it, what changed and which record it touched: filterable by model, operation, role and date.

What does the DPDP Act 2023 mean for school data?

Edutris is designed for the Digital Personal Data Protection Act, 2023: schools direct how their students' data is used, parents see their own children's information and nothing else, and data handling is structured so the school can meet its obligations as the data fiduciary. Student and guardian data is processed for running the school (attendance, fees, academics, communication) not for advertising.

Which security controls does Edutris run?

Encryption in transit

All traffic between devices and Edutris servers is protected with SSL/TLS, logins, the parent app, and every API call.

Role-based access

Seven role-based portals with granular permissions: a teacher sees their classes, the office sees what it administers, parents see only their own children.

Per-school data isolation

Multi-tenant architecture with every query scoped to the school. A trust's campuses share an account, never each other's raw data.

Activity audit logs

Changes leave a trail, so the school can always answer who changed what, and when.

Automated backups

Scheduled database backups with rotation, so the school's record survives hardware failure or mistakes.

Input validation throughout

Server-side validation and scoped queries as standard engineering practice, not an afterthought.

How reliable is it, and who answers when you get in touch?

Edutris is cloud-hosted with always-on health monitoring and an internal uptime target. We deliberately say target, not guarantee. We don't sell an SLA we can't evidence, and vendors who promise '100% uptime' are telling you about their marketing, not their infrastructure.

Support is real people familiar with Indian school workflows, not a generic call centre. We don't publish support hours or a response-time commitment, for the same reason we don't sell an uptime SLA: we would rather state nothing than state something we cannot stand behind.

Which certifications does Edutris not hold?

You'll notice this page has no certification badges. Edutris does not currently hold ISO 27001 or SOC 2 certification, and we won't display badges we haven't earned. What we do offer is the specific, verifiable set of controls above, and straight answers to any security question during your evaluation. Ask us the hard ones at the demo.

What security questions should you ask a vendor?

"Where does our data live, and who can see it?"

You should get a specific answer about isolation between schools and role-based access inside yours.

"What happens if we leave?"

Your data is yours. Edutris supports exporting your records: ask for the specifics in your evaluation.

"Show me the audit trail."

If a vendor can't show who changed a student's marks and when, the register isn't really a system of record.

"What's your backup and recovery story?"

Automated, scheduled, rotated backups, and a straight answer on restore.

Frequently asked questions

How does Edutris approach India's DPDP Act 2023?

Edutris is built around the DPDP Act 2023, role-based access, per-school data isolation, encryption in transit, audit logs and processing under the school's direction as data fiduciary. Schools remain the controllers of their students' data.

Who owns the school's data?

The school does. Edutris processes it to run the school's operations, and supports exporting your records if you ever leave.

Does Edutris have ISO 27001 or SOC 2 certification?

Not currently, and we won't show badges we haven't earned. This page lists the specific controls we do operate: encryption in transit, role-based access, tenant isolation, audit logging and automated backups.

Is there an uptime guarantee?

We operate to an internal uptime target with always-on health monitoring. We deliberately call it a target rather than a contractual SLA, because we'd rather be precise than impressive.

Sources

  1. DPDP Rules, 2025: notified (Press Information Bureau, Government of India), Read 2026-09-11. Records that the Rules were notified on 14 November 2025, giving full effect to the Digital Personal Data Protection Act, 2023, with an eighteen-month phased compliance period. On children: “verifiable consent from a parent or guardian is required… unless the processing relates to essential services such as healthcare, education or real-time safety.”

See it running on a real school, in 20 minutes.

Guided onboarding included · Structured setup on your workflow · Tiers from ₹2,999/month

Book a demo →