Hosted in India
Servers in an Indian data centre region. Data residency that respects your audit. We can name the region on the walkthrough.
Schools handle sensitive information on minors and their families. This page sets out how Nexadium stores, protects and returns that data.
Servers in an Indian data centre region. Data residency that respects your audit. We can name the region on the walkthrough.
TLS 1.3 between every browser and our servers. AES-256 on every byte at rest. Passwords hashed with industry-standard algorithms, never stored in clear.
Automated backups every twenty-four hours with point-in-time recovery on the primary database. Tested restore drill quarterly, not just claimed.
The accountant can issue receipts. The class teacher can mark attendance. The front-office cannot see salaries. You define it, down to the action.
Every meaningful action (fee edits, concessions, refunds, role changes) is logged with who, what, when. The log itself cannot be edited from inside the app.
Export to Excel and PDF is built into the product. We do not lock data away to make leaving harder.
Your school's data (students, parents, fees, receipts) is stored on infrastructure within India. Backups remain within India. Cross-border replication is opt-in, not default.
Role-based access controls what users can do. The audit log records what they did, and is what an auditor or trustee will ask for.
Pre-built roles cover the common school structure: principal, accountant, front-office, class teacher, parent. Custom roles can be created down to the action level: collect payment, approve concession, view salary, edit fee structure.
Every elevated action (granting roles, issuing refunds, editing a fee structure) can be gated on a second approval if your school's policy requires it.
A non-exhaustive list of audited events
The audit log itself is append-only from inside the application. Records cannot be edited or deleted by any role.
Every list and every report exports to Excel and PDF in-product, today. No quota, no approval queue.
Month-to-month and annual plans, with no multi-year tie-in. Your reason to stay is the product working, not a contract.
Thirty-day clean-export window after cancellation, then permanent deletion from primary systems. Backups age out within ninety days.
We do not use your data for product analytics, model training, or third-party AI. Any future AI feature is opt-in per school, in writing.
The controls below map to the standards IT and compliance teams typically evaluate. Documentation is available for review under NDA.
Our security controls are designed and operated against the SOC 2 trust principles: security, availability and confidentiality. Your IT or compliance team can review our controls documentation under NDA.
Information-security management follows ISO 27001 practice across access control, encryption, backup and incident response. The control mapping is available for your team to review under NDA.
Continuous internal security review, plus independent third-party penetration testing. Executive summaries are shared with schools under NDA on request.
For deeper review by your IT or compliance team, the Nexadium team can schedule a working session and share documentation under NDA.