Legal

Security Architecture

Last updated: September 2026

1. Multi-Tenant Data Isolation

EduiQo utilizes a strict multi-tenant architecture. This ensures that every institution's data is logically separated at the database level. Queries are strictly scoped, preventing any cross-pollination of sensitive student, financial, or staff records.

2. Data Encryption

Data is secured both at rest and in transit. We use industry-standard AES-256 encryption for data at rest and TLS 1.2+ for all data in transit between your browser and our servers.

3. Role-Based Access Control (RBAC)

Access to modules and data within an institution is governed by granular role-based permissions. A teacher can only see their assigned classes, an accountant can only access financial data, and admins retain full oversight. Custom roles can be tailored to your specific organizational structure.

4. Infrastructure Security

EduiQo is hosted on tier-1 cloud providers. We employ Web Application Firewalls (WAF), regular vulnerability scanning, and strict network security groups to protect against DDoS attacks and unauthorized intrusions.

5. Audit Logs

Critical actions—such as fee collection, grade modifications, or role changes—are logged with immutable audit trails. Administrators can review who took what action, and when, ensuring total accountability.

6. Data Backups

We perform automated daily backups of all institutional data. Backups are encrypted and stored in geographically redundant locations to ensure fast disaster recovery in case of catastrophic events.

7. Reporting Security Issues

If you believe you have found a security vulnerability in EduiQo, please contact us immediately at info@eduiqo.com. We investigate all reports promptly.