SECURITY ISO 27001 ยท SOC 2 Type II ยท DPDP 2023

Enterprise security, India-first compliance.

Schools handle the most sensitive data on the planet โ€” children's records. We treat security, DPDP compliance, and uptime as product features, audited every year, never as marketing claims.

99.9% uptime 256-bit encryption AWS Mumbai region Zero breaches since 2019
99.9%
Uptime over last 12 months
256bit
AES encryption everywhere
ISO 27001
Certified since 2024
0
Data breaches in 7 years
CERTIFICATIONS

Audited by independent third-party assessors.

Every certificate below is renewed annually by a Big Four or empanelled CERT-In auditor. Reports are available under NDA on request.

๐Ÿ›ก๏ธ

ISO 27001:2022

Cert ยท IS-739104

Information security management system, audited by BSI India. Renewed annually with quarterly internal reviews.

๐Ÿ“‹

SOC 2 Type II

12-month observation

Security, availability, confidentiality, and processing integrity audited by Deloitte over a continuous 12-month window.

๐Ÿ‡ฎ๐Ÿ‡ณ

DPDP Act, 2023

Compliant ยท DPO appointed

Full Digital Personal Data Protection Act compliance. Designated Data Protection Officer. Consent flows for all student data.

๐ŸŒ

GDPR

EU representative ยท DPA ready

Compliant for international schools serving EU students. Standard contractual clauses and EU representative on file.

๐Ÿ›๏ธ

NDPS-aligned

India National Data Policy

Architected to align with India's National Data Policy on storage, classification, and lawful access of personal data.

๐Ÿ”

CERT-In empanelled

VAPT ยท Annual

VAPT testing performed every 6 months by a CERT-In empanelled security auditor. Findings tracked to closure within 30 days.

DATA PROTECTION

Your students' data, protected by design.

Encryption, residency, and access control at every layer of the stack.

Encryption at rest and in transit

Every byte of student, fee, and parent data is encrypted with AES-256 at rest. All connections use TLS 1.3 with perfect forward secrecy. Encryption keys are managed in AWS KMS with hardware security modules (FIPS 140-2 Level 3).

  • AES-256 encryption for all databases and S3 buckets
  • TLS 1.3 enforced โ€” no fallback to older protocols
  • HSM-backed KMS keys, rotated every 90 days
  • Field-level encryption for Aadhaar, PAN, and bank details
AES-256
End-to-end encryption ยท TLS 1.3

AWS Mumbai data residency

All AskCampus data is stored exclusively in the AWS Asia Pacific (Mumbai) region โ€” ap-south-1. Backups replicate within India to AWS Hyderabad. Your data never leaves Indian soil unless you explicitly request a cross-border export.

  • Primary: AWS Mumbai (ap-south-1) โ€” 3 availability zones
  • DR: AWS Hyderabad (ap-south-2) โ€” async replication
  • Zero data egress to non-Indian regions
  • Sovereign-cloud option available on Scale plan
๐Ÿ‡ฎ๐Ÿ‡ณ
100% India-resident
Mumbai primary ยท Hyderabad DR

Role-based access control

Granular permissions for principals, teachers, accountants, and parents. Every action is logged with user, IP, device, and timestamp โ€” exportable as a CSV audit trail for your auditors and trustees.

  • 14 default roles, fully customisable per institution
  • SSO via Google, Microsoft, and SAML 2.0
  • Mandatory 2FA for admin and finance roles
  • Immutable audit log retained for 7 years
14
Pre-built roles ยท 2FA enforced ยท 7-year audit trail
OPERATIONAL SECURITY

The discipline behind 99.9% uptime.

Real engineers, real runbooks, real on-call rotations โ€” not a status page promise.

๐Ÿ“ก

24/7 monitoring

Datadog and PagerDuty watch 1,400+ metrics across infrastructure and application layers. Two-engineer on-call rotation, 24/7, 365 days.

  • Mean time to acknowledge: 4 minutes
  • Synthetic monitoring from 6 Indian cities
  • Real-time customer status page
๐Ÿšจ

Incident response

Documented runbooks for 47 incident types. Customer notification within 15 minutes of confirmed Sev-1. Public RCA within 5 working days.

  • Sev-1 acknowledgement SLA: 15 minutes
  • Bilingual incident comms (English + Hindi)
  • CISO briefs trustees directly on Sev-1 events
๐Ÿ’พ

Backups & recovery

Hourly snapshots, daily full backups, 35-day retention. Tested DR drill every quarter with a documented RPO of 5 minutes and RTO of 60 minutes.

  • RPO: 5 minutes ยท RTO: 60 minutes
  • Quarterly tested failover to Hyderabad region
  • Per-tenant restore on request, free of charge
PRIVACY & DPDP

Built for India's data protection law.

The DPDP Act 2023 isn't a checkbox for us โ€” it's how we designed consent, retention, and breach notification from the ground up.

Consent, retention, and your rights

We collect only the data your institution needs to operate โ€” and we make it easy for parents and students to exercise their rights under DPDP. Our Data Protection Officer is contactable directly at dpo@askcampus.io.

  • Granular parental consent for under-18 student data
  • Configurable retention windows per data category
  • Self-serve data access, correction, and erasure portal
  • 72-hour breach notification to Data Protection Board
  • Data Processing Addendum (DPA) signed with every customer
72h
Breach notification SLA ยท DPDP-aligned
TRUST RESOURCES

Don't take our word for it โ€” verify everything.

๐Ÿ›

Bug bounty programme

Public responsible-disclosure programme on HackerOne. Rewards from โ‚น5,000 (low) to โ‚น5,00,000 (critical). 84 valid reports closed since 2023.

๐Ÿ“Š

Live status page

status.askcampus.io shows real-time health of every service, region-by-region. Subscribe via email or RSS for incident updates.

๐Ÿ“‘

Audit reports on request

SOC 2 Type II report, ISO 27001 certificate, VAPT summary, and pen-test letters available under NDA from your account manager.

WHAT TRUSTEES SAY

The reason CFOs sign our renewal.

โ˜…โ˜…โ˜…โ˜…โ˜…

"Our IT committee asked for ISO 27001, SOC 2, and DPDP DPA โ€” AskCampus had all three in our inbox by Monday morning. That doesn't happen with most vendors."

VM
Vikram Mehta
Trustee, Greenfield Public School
โ˜…โ˜…โ˜…โ˜…โ˜…

"As a CBSE+IB school we host EU-citizen children. AskCampus's GDPR-ready DPA and EU representative made our parents' lawyers comfortable in one call."

MN
Meera Narayan
Principal, Sunrise International
โ˜…โ˜…โ˜…โ˜…โ˜…

"Their CISO got on a Sunday call when our trustees had questions. That's the moment we knew this wasn't a typical SaaS vendor."

DV
Dr. Deepak Vaidya
Chairman, Vidya Bhavan Group
DETAILED COMPLIANCE MAP

Six frameworks, independently audited.

Every framework below has a current letter of attestation on file with our compliance team. Auditor names, scope statements, and last-audited dates are listed verbatim โ€” exactly what an empanelled auditor or trustee committee would see in our SIG questionnaire.

ISO

ISO/IEC 27001:2022

Cert IS-739104 ยท BSI India
Scope
Full SaaS platform
Cadence
Annual + quarterly internal
Last audit
14 February 2026

Our Information Security Management System covers the entire AskCampus SaaS platform โ€” Mumbai primary, Hyderabad DR, all engineering offices, and every laptop fleet. BSI India performs the annual surveillance audit and we run our own quarterly internal review. The audit report is downloadable under NDA from your account manager.

SOC

SOC 2 Type II

Deloitte ยท 12-month window
Scope
Security, availability, confidentiality
Cadence
Continuous 12-month observation
Last audit
Period closed 31 March 2026

Deloitte India audits our platform continuously over a rolling twelve-month observation window covering five Trust Services Criteria. The current attestation report (period 1 Apr 2025 โ€“ 31 Mar 2026) carries a clean opinion with zero exceptions. Annual addressable audit costs over โ‚น1.4 crore โ€” passed entirely as a customer benefit.

DPDP

DPDP Act, 2023

DPO appointed ยท India-resident
Scope
All personal data processing
Cadence
Continuous self-assessment
Last review
20 March 2026

Full Digital Personal Data Protection Act compliance with a designated Data Protection Officer (Ms. Anu Subramaniam, dpo@askcampus.io). Consent receipts, granular parental consent for under-18 users, configurable retention windows by data category, and a 72-hour breach notification SLA are all wired into the product, not added as documentation.

GDPR

GDPR (EU)

SCC ยท EU representative
Scope
EU-citizen students at IB schools
Cadence
Annual legal review
Last review
11 January 2026

For our IB and IGCSE customers serving EU-citizen children, we sign Standard Contractual Clauses, maintain an EU-based representative (Mannheim, Germany), and keep an Article 30 record of processing activities. Cross-border transfers default to "off" โ€” explicit institution sign-off is required to enable any data flow outside India.

CIN

CERT-In Empanelment

VAPT ยท 6-monthly
Scope
Web app, mobile, API surface
Cadence
Every 6 months
Last audit
27 February 2026

Vulnerability assessment and penetration testing performed every six months by a CERT-In empanelled auditor (currently SISA Information Security). All Sev-1 and Sev-2 findings tracked to closure within 30 days; the closure letter is shared with customers on request. Last audit cycle closed with zero outstanding Sev-1 findings.

NIST

NIST CSF 2.0

Self-assessed ยท Tier 4
Scope
All six functions, full org
Cadence
Annual self-assessment
Last review
5 March 2026

We map every internal control to the NIST Cybersecurity Framework 2.0 across the six functions โ€” Govern, Identify, Protect, Detect, Respond, Recover. Current self-assessed maturity is Tier 4 (Adaptive) on five of six functions, Tier 3 (Repeatable) on Govern. The full mapping spreadsheet is shared with prospects under NDA.

DATA FLOW & RESIDENCY

Where your data goes, step by step.

From the moment a parent taps "Pay fees" on the mobile app to the moment a backup tape lands in our Hyderabad DR region โ€” the four stops every byte makes. No surprise stops in Singapore, Frankfurt, or Virginia.

1
๐Ÿ“ฑ

Client device

Browser or mobile app initiates the request. TLS 1.3 with perfect forward secrecy is enforced before any payload leaves the device. Connection is pinned to *.askcampus.io โ€” no fallback to weaker ciphers, no permissive HTTPS.

2
๐Ÿ‡ฎ๐Ÿ‡ณ

Mumbai data centre

Request terminates at our AWS Asia Pacific (Mumbai) ap-south-1 edge โ€” three availability zones, multi-AZ load balancers, IST-aligned ops team. The originating customer tenant is identified, request is signed, and routing decisions are made entirely inside India.

3
๐Ÿ”

Encryption at rest

Data lands in tenant-isolated PostgreSQL and S3 with AES-256 at rest, FIPS 140-2 Level 3 HSM-backed KMS keys rotated every 90 days. Aadhaar, PAN, and bank account fields receive an additional layer of application-level field encryption.

4
๐Ÿ’พ

Hyderabad backups

Hourly snapshots and daily fulls replicate asynchronously to AWS Hyderabad (ap-south-2) over a private VPC peering link. Retention is 35 days. Quarterly DR drills failover the entire stack inside a 60-minute RTO with a 5-minute RPO.

OPERATIONAL SECURITY PLAYBOOK

The six routines that prevent the headline.

Certifications are necessary but not sufficient. The day-to-day security playbook below is what actually keeps the breach count at zero across seven years of operation. Every item runs on a published schedule with documented owners.

๐Ÿ“ก

24/7 SOC

โ— Always-on monitoring

Two-person on-call rotation in our Hyderabad SOC, backed by Datadog SIEM and PagerDuty escalation. 1,400+ metrics watched continuously. Mean time to acknowledge: 4 minutes. Sev-1 escalation reaches the CISO inside 15 minutes, day or night.

๐Ÿšจ

Incident response

โ— P1 SLA < 15 minutes

Documented runbooks for 47 incident classes, rehearsed quarterly. Customers receive a confirmed Sev-1 notification within 15 minutes, an interim update every 30 minutes, and a public RCA within five working days. Bilingual (English + Hindi) comms by default.

๐Ÿงช

Quarterly DR drills

โ— Q1 2026 drill: passed

Every quarter we failover the full production stack from Mumbai to Hyderabad with real customer load on synthetic tenants. RPO is measured at 5 minutes, RTO at 60 minutes. The post-drill report is reviewed by the CISO and shared with enterprise customers.

๐ŸŽฃ

Phishing simulations

โ— Monthly ยท all 320+ staff

Every employee โ€” engineering, sales, support, legal โ€” receives a monthly simulated phishing email from our internal red team. Click-rate target is <3%; current 12-month rolling average is 1.4%. Click-through triggers automated retraining and SOC alert.

๐Ÿ›

Bug bounty

โ— Up to โ‚น5,00,000 per finding

Public responsible-disclosure programme on HackerOne since 2023. Rewards range from โ‚น5,000 (Low) to โ‚น5,00,000 (Critical). 84 valid findings processed to date with a 9-day median time to fix. Hall of Fame published on our trust portal.

๐Ÿงพ

Vendor security reviews

โ— Annual ยท 100% of vendors

Every sub-processor โ€” payment gateways, SMS providers, cloud, observability tools โ€” passes an annual vendor security assessment. Vendors that fail to renew SOC 2 / ISO 27001 are replaced inside one quarter. The full sub-processor list is published on our trust portal.

ROLES, ACCESS, AND AUDIT

Granular RBAC, immutable audit logs.

Every action a user performs โ€” viewing a fee balance, downloading a marksheet, exporting a parent list โ€” is recorded with user, IP, device, and timestamp on a write-once log retained for seven years.

Role-based access control, by design

AskCampus ships with 14 default roles modelled on real Indian school structures โ€” Trustee, Principal, Vice Principal, Head Teacher, Class Teacher, Subject Teacher, Accountant, Admissions Officer, Front Office, Transport In-Charge, Hostel Warden, Librarian, Parent, Student. Every role can be cloned and customised at the institution level without touching production code or filing a support ticket.

  • 14 default roles, infinite custom roles per tenant
  • Field-level permissions on sensitive data (Aadhaar, fees, marks, medical)
  • Mandatory two-factor authentication for admin and finance roles
  • Single sign-on via Google Workspace, Microsoft Entra ID, and SAML 2.0
  • Just-in-time elevation with four-eyes approval for production data access
7yr
Immutable audit log retention ยท Exportable CSV / SIEM stream
Sample log line
2026-04-28T14:22:11+05:30 ยท user=acct.priya@dps ยท role=Accountant ยท action=fee.view ยท student=A4172 ยท ip=49.207.x.x
CUSTOMER SECURITY FAQ

Eight questions every IT committee asks.

The compressed version of our standard SIG-Lite response. If something below needs more depth โ€” a data flow diagram, a sub-processor list, an incident statistic โ€” your account manager can get it to you under NDA inside one working day.

Where exactly is our school's data stored?

Primary copy lives in AWS Asia Pacific (Mumbai) ap-south-1 across three availability zones. Async-replicated backups live in AWS Hyderabad ap-south-2. No data ever leaves Indian soil unless you explicitly enable the cross-border export feature on the Scale plan, which is off by default.

Who at AskCampus can access our production data?

A standing list of 9 named SREs and 2 named DBAs, all India-resident background-checked employees. Production access requires SSO + hardware-key 2FA + just-in-time approval from a second engineer, with every keystroke recorded to a separate immutable audit stream we cannot edit.

How quickly will we be told if there is a breach?

Our DPDP-aligned customer SLA is breach notification within 72 hours of confirmation. In practice, our last three customer-impacting Sev-1 incidents (none of which involved data exposure) were communicated within 22, 14, and 9 minutes respectively. We err heavily on the side of telling you fast.

Can we get a copy of your SOC 2 and ISO certificates?

Yes. The ISO 27001 certificate is downloadable from our public trust portal. The SOC 2 Type II report and the CERT-In VAPT closure letter require a one-page mutual NDA, which your account manager can turn around in one working day.

Do you support SSO with our existing identity provider?

Yes โ€” Google Workspace, Microsoft Entra ID (Azure AD), Okta, and any SAML 2.0 / OIDC provider on Scale plan. Group-to-role mapping is automatic. SCIM 2.0 user provisioning and de-provisioning is supported, so off-boarded staff lose access in real time.

What happens to our data if we leave AskCampus?

You receive a full export โ€” students, parents, fee history, marks, attendance, payroll โ€” in CSV and JSON inside seven days of contract termination, free of charge. After a 30-day grace window, all production and backup data is cryptographically erased and a written attestation is provided.

Is our data ever used to train AI models?

No. Customer data is never used to train shared or third-party models. AskCampus AI features run on per-tenant inference only, with no cross-tenant signal. Your data does not leave your tenant boundary except for the operational replication described in the data-flow diagram above.

Can we run a penetration test against our tenant?

Yes โ€” on the Scale plan, with seven days' notice, in our staging environment with mirrored production data. We will share the rules of engagement, the sub-processor allow-list, and the escalation contacts. We have hosted 11 customer-led pen-tests in the last 12 months without incident.

Have a security question?

Our CISO and Data Protection Officer respond personally to security questionnaires from trustees, IT committees, and parent groups โ€” usually within one working day.

Email security@askcampus.io โ†’

See the platform our CISO would deploy.

30-minute walkthrough of the security architecture with a senior solutions consultant. NDA, DPA, and audit reports available on request.

ISO 27001 ยท SOC 2 Type II ยท DPDP 2023 ยท GDPR ยท AWS Mumbai
Chat with us
See AskCampus in action โ€” book a free 30-minute demo with a senior solutions consultant. Tailored to your institution.
S
๐Ÿ‘‹ Hi, I'm Sara
Online now
Questions about admissions, fees, attendance, parent app, pricing, or migrating from your current school ERP? Ask me โ€” I'm online.