Skip to content

Trust & security

Trust centre

Where EduGradUP stores your data, who can access it, and how we prove it — for principals, owners, IT teams and DPOs.

PDPA Compliant (Singapore)

Annual third-party assessment, named DPO per tenant, published Personal Data Protection Notice.

DPDP Act Aligned (India)

Data fiduciary obligations covered, breach-notification SLAs documented, consent management framework.

ISO 27001 Aligned ISMS

Documented Information Security Management System covering access control, change management and incident response. Statement of Applicability and audit scope available under NDA.

SOC 2 Type II (in progress)

Observation window underway with an independent auditor; bridge letter available to enterprise prospects on request.

AWS Singapore residency

Primary region ap-southeast-1 for SG/BD/NP tenants; ap-south-1 (Mumbai) for India tenants. Cross-region encrypted backups.

GDPR-ready

Data Processing Addendum with Standard Contractual Clauses for European school groups; Article 30 records, DPbD by default, right-to-erasure within 30 days.

OWASP Top 10 + ASVS L2

Annual penetration test by an independent firm, with executive summary available under NDA.

Security questionnaire ready

Pre-answered SIG-Lite and CAIQ (CSA STAR) responses in our trust pack — sent the same day under NDA, no partner hand-off.

Data residency by country

Access control

Role-based access with least-privilege defaults. Every admin action is logged with actor, timestamp, IP and previous/new value. Audit logs are retained for 7 years for Singapore and 5 years elsewhere.

Backups & recovery

Encrypted daily snapshots with 35-day retention, cross-region copies, and a documented restore drill executed quarterly with RTO 4 hours and RPO 24 hours.

Sub-processors

Full list available on request and updated at every contract renewal. Schools are notified 30 days in advance of any change to sub-processors handling personal data.

API & integration security

EduGradUP exposes a documented REST API for SIS, accounting and identity integrations. Authentication uses OAuth 2.0 (authorization-code and client-credentials flows) plus scoped API keys that you can rotate yourself from Setup → Developers. Every key is least-privilege and limited to named modules.

Certifications & evidence

We share proof, not just claims. Available the same day under a mutual NDA:

Security questionnaire

IT teams do not need to start from a blank questionnaire. Our trust pack ships pre-answered SIG-Lite and CAIQ (CSA STAR) responses, plus a VPAT-style accessibility statement. Send your own template to security@schoolsoftwareindia.com and we return it completed, typically within two business days, with no third-party hand-off.

GDPR & data-protection law

For European school groups and international schools, EduGradUP acts as a data processor under a Data Processing Addendum that incorporates the EU Standard Contractual Clauses.

Reporting a vulnerability

Email security@schoolsoftwareindia.com. We acknowledge within 24 hours and have a published 90-day coordinated-disclosure policy. We do not pursue legal action against good-faith security research.

Ready to see EduGradUP in your school?

Book a free 30-minute demo in Bengali, Nepali or English. Free data migration. 14-day trial. No credit card.

  • ✓ 4-hour response SLA
  • ✓ PDPA & DPDPA aligned
  • ✓ bKash · eSewa · PayNow · UPI ready