PDPA Compliant (Singapore)
Annual third-party assessment, named DPO per tenant, published Personal Data Protection Notice.
Trust & security
Where EduGradUP stores your data, who can access it, and how we prove it — for principals, owners, IT teams and DPOs.
Annual third-party assessment, named DPO per tenant, published Personal Data Protection Notice.
Data fiduciary obligations covered, breach-notification SLAs documented, consent management framework.
Documented Information Security Management System covering access control, change management and incident response. Statement of Applicability and audit scope available under NDA.
Observation window underway with an independent auditor; bridge letter available to enterprise prospects on request.
Primary region ap-southeast-1 for SG/BD/NP tenants; ap-south-1 (Mumbai) for India tenants. Cross-region encrypted backups.
Data Processing Addendum with Standard Contractual Clauses for European school groups; Article 30 records, DPbD by default, right-to-erasure within 30 days.
Annual penetration test by an independent firm, with executive summary available under NDA.
Pre-answered SIG-Lite and CAIQ (CSA STAR) responses in our trust pack — sent the same day under NDA, no partner hand-off.
Role-based access with least-privilege defaults. Every admin action is logged with actor, timestamp, IP and previous/new value. Audit logs are retained for 7 years for Singapore and 5 years elsewhere.
Encrypted daily snapshots with 35-day retention, cross-region copies, and a documented restore drill executed quarterly with RTO 4 hours and RPO 24 hours.
Full list available on request and updated at every contract renewal. Schools are notified 30 days in advance of any change to sub-processors handling personal data.
EduGradUP exposes a documented REST API for SIS, accounting and identity integrations. Authentication uses OAuth 2.0 (authorization-code and client-credentials flows) plus scoped API keys that you can rotate yourself from Setup → Developers. Every key is least-privilege and limited to named modules.
We share proof, not just claims. Available the same day under a mutual NDA:
IT teams do not need to start from a blank questionnaire. Our trust pack ships pre-answered SIG-Lite and CAIQ (CSA STAR) responses, plus a VPAT-style accessibility statement. Send your own template to security@schoolsoftwareindia.com and we return it completed, typically within two business days, with no third-party hand-off.
For European school groups and international schools, EduGradUP acts as a data processor under a Data Processing Addendum that incorporates the EU Standard Contractual Clauses.
Email security@schoolsoftwareindia.com. We acknowledge within 24 hours and have a published 90-day coordinated-disclosure policy. We do not pursue legal action against good-faith security research.
Book a free 30-minute demo in Bengali, Nepali or English. Free data migration. 14-day trial. No credit card.