Security, in plain language.
OptiCloud handles student records, fee data, and institutional communications across all our products. Here's exactly how we protect them — and what we're still building.
How your data is isolated.
Multi-tenant architecture with strict data isolation — every institution's data lives in its own logical boundary. No shared tables. No cross-tenant access at the database level.
- Comprehensive data model, isolated end-to-end per institution
- Row-level security enforced at the data access layer for every query
- An institution literally cannot read another institution's data
Strict tenant isolation
Institution A
tenant_a
Institution B
tenant_a
Institution C
tenant_a
Who can access what.
Industry-standard authentication
Hardened session management. HTTP-only cookies, CSRF protection, automatic expiry.
Role-based access control
11 roles with field-level permissions. Configurable sharing rules per object.
Password hashing
Industry-standard password hashing with strong work factor. Never stored in plain text. Never visible to staff.
Audit log
Every sensitive action logged with user, timestamp, and IP. Tamper-evident on the database side.
Token-based API authentication
Short-lived tokens for programmatic access. Token rotation supported.
Session security
Auto-expiry on inactivity. Forced reauthentication for sensitive operations.
What happens to your data.
In transit
TLS 1.2+ for all connections. HSTS enforced. No mixed-content paths.
At rest
Database encrypted at the storage layer.
Backups
Daily automated backups with 30-day retention. Tested restores quarterly.
File storage
Encrypted object storage with time-limited, authenticated URLs — files only accessible to the right user, for the right window.
How your data is protected.
What we provide for each layer of your data — described in user-benefit terms, not internal stack names.
Where we are on compliance.
Honesty about what's in place, what's in progress, and what isn't yet. This is more credible than a wall of claimed certifications.
In place today
- DPDP Act 2023 (India) — data handling aligned with the Digital Personal Data Protection Act
- PCI-DSS compliance inherited at the payment processor — card data never touches our systems
- DLT-registered SMS templates for India compliance
In progress
- ISO 27001 — preparation underway
- SOC 2 Type 1 — scoping discussions with auditors
Not yet
- SOC 2 Type 2 — requires 6+ months of evidence collection
- GDPR formal certification — EU customers served under contract-based DPA in the meantime
If something goes wrong.
72-hour notification
We notify affected institutions within 72 hours of any confirmed data incident.
Public post-mortems
Post-mortems are published for any production-impacting events. Transparency is part of the trust we're trying to earn.
Subprocessors we work with.
Every third-party service that processes your data, the data category involved, and where it's processed. Disclosed for DPDP compliance.
Enterprise evaluating OptiCloud?
Request our detailed security questionnaire — covers architecture, controls, subprocessor list, and compliance evidence.
Request the questionnaire