Data Security Policy
At SHAALAOS (operated by ACADERS EDUVERSITY PRIVATE LIMITED), safeguarding student academic records, fee transaction data, and institutional privacy is our foundational commitment.
1 Multi-Tenant Data Isolation
SHAALAOS is engineered with strict multi-tenant boundary controls. Each subscribing school operates in an isolated environment with row-level and database-level partition checks applied automatically on every single request. Cross-tenant data leakage is strictly prevented at the core framework level.
2 End-to-End Data Encryption
- Data in Transit: All HTTP traffic between client web browsers, mobile apps, and SHAALAOS servers is encrypted using modern TLS 1.3 / SSL 256-bit encryption with strict HSTS enforcement.
- Data at Rest: Database storage and sensitive record fields are encrypted using industry-standard AES-256 encryption algorithms.
- Password Hashing: User credentials are never stored in plain text and are protected using one-way BCrypt hashing with unique cryptographic salt values.
3 Infrastructure & Cloud Security
Our infrastructure partners provide Tier-3/4 enterprise data center security:
- Cloud Data Centers: Hosted on AWS / Cloudflare enterprise cloud infrastructure equipped with 24/7 physical security, biometric access controls, and climate regulation.
- DDoS Mitigation: Automated distributed denial-of-service (DDoS) filtering and Web Application Firewall (WAF) rule sets to block malicious traffic spikes.
- Continuous Vulnerability Scans: Server operating systems and application dependencies receive automated security patch updates and vulnerability audits.
4 Automated Backups & Disaster Recovery
- Daily Encrypted Snapshots: Automated full database snapshots are taken daily and stored in geographically redundant, encrypted storage.
- Point-in-Time Recovery: Granular recovery mechanisms enable rapid data restoration in the event of accidental institutional deletion or emergency hardware events.
- RTO & RPO Targets: Low Recovery Time Objective (RTO) and Recovery Point Objective (RPO) guarantees ensure minimal operational downtime.
5 Role-Based Access Control (RBAC)
Access to student and financial data is strictly controlled through granular Role-Based Access Controls (RBAC). School administrators control staff permissions, ensuring teachers, parents, and students can only access records specifically assigned to their verified user role.
6 Incident Response & Security Contact
Our technical team maintains a dedicated security monitoring desk. In the unlikely event of a security incident affecting institutional data, SHAALAOS adheres to a mandatory 72-hour notification protocol for affected school administrators.
ACADERS EDUVERSITY PRIVATE LIMITED
Email: support@acaders.in · security@shaalaos.com