Built in India · Hosted in India · No long-term contracts

Security & data

Data you can trust,
and take with you.

Schools handle sensitive information on minors and their families. This page sets out how Nexadium stores, protects and returns that data.

Hosted in India

Servers in an Indian data centre region. Data residency that respects your audit. We can name the region on the walkthrough.

Encrypted everywhere

TLS 1.3 between every browser and our servers. AES-256 on every byte at rest. Passwords hashed with industry-standard algorithms, never stored in clear.

Backed up daily, restorable in 4 hours

Automated backups every twenty-four hours with point-in-time recovery on the primary database. Tested restore drill quarterly, not just claimed.

Granular role-based access

The accountant can issue receipts. The class teacher can mark attendance. The front-office cannot see salaries. You define it, down to the action.

Immutable audit log

Every meaningful action (fee edits, concessions, refunds, role changes) is logged with who, what, when. The log itself cannot be edited from inside the app.

Your data is yours

Export to Excel and PDF is built into the product. We do not lock data away to make leaving harder.

Where your data lives

Data hosted within India.

Your school's data (students, parents, fees, receipts) is stored on infrastructure within India. Backups remain within India. Cross-border replication is opt-in, not default.

  • Transport. HTTPS-only with HSTS. TLS 1.3 with modern cipher suites; older protocols rejected.
  • Application. Authentication is per-user, per-school. Anti-CSRF tokens on every form. Session tokens scoped to the tenant.
  • Storage. AES-256 at rest on the primary database. File uploads encrypted with separate per-tenant keys.
  • Secrets. Connection strings, API keys and certificates managed in a hardware-backed secret store; never in source control.
  • Backups. Daily full snapshots plus continuous transaction-log shipping. Encrypted at rest. Restore tested quarterly.
Access & audit

Who saw what.
When and why.

Role-based access controls what users can do. The audit log records what they did, and is what an auditor or trustee will ask for.

Role-based access, granular by default

Pre-built roles cover the common school structure: principal, accountant, front-office, class teacher, parent. Custom roles can be created down to the action level: collect payment, approve concession, view salary, edit fee structure.

Every elevated action (granting roles, issuing refunds, editing a fee structure) can be gated on a second approval if your school's policy requires it.

A non-exhaustive list of audited events

  • Fee receipt issued Counter / online, every receipt
  • Receipt cancelled With reason, timestamp, and operator identity
  • Concession applied Approver, type, value, head
  • Concession withdrawn Reason, approver, timestamp
  • Refund processed Linked back to the original receipt
  • Fee structure changed Old value → new value, by whom, when
  • Role granted or revoked User, role, granting administrator
  • Login from new device User, device fingerprint, IP, location
  • Data export downloaded Who, what scope, when; every export is traceable
  • Student record edited Field-level diff retained for accountability

The audit log itself is append-only from inside the application. Records cannot be edited or deleted by any role.

Data ownership & exit

Leaving us should be as easy as joining us.

Built-in exports

Every list and every report exports to Excel and PDF in-product, today. No quota, no approval queue.

No lock-in

Month-to-month and annual plans, with no multi-year tie-in. Your reason to stay is the product working, not a contract.

Retention & deletion

Thirty-day clean-export window after cancellation, then permanent deletion from primary systems. Backups age out within ninety days.

No data training

We do not use your data for product analytics, model training, or third-party AI. Any future AI feature is opt-in per school, in writing.

Verification

Controls you can verify.

The controls below map to the standards IT and compliance teams typically evaluate. Documentation is available for review under NDA.

On request

SOC 2 trust principles

Our security controls are designed and operated against the SOC 2 trust principles: security, availability and confidentiality. Your IT or compliance team can review our controls documentation under NDA.

On request

ISO 27001 practices

Information-security management follows ISO 27001 practice across access control, encryption, backup and incident response. The control mapping is available for your team to review under NDA.

On request

Independent penetration testing

Continuous internal security review, plus independent third-party penetration testing. Executive summaries are shared with schools under NDA on request.

Common questions

Questions an IT lead or auditor will ask.

On Microsoft Azure infrastructure, in an Indian region. We can name the specific region on the walkthrough. Backups remain within Indian data centres.
Yes. Excel and PDF exports are available in the product, before and after notice of cancellation. Your data is yours, and exit is your right.
We retain it for thirty days for a clean export window, then it is permanently deleted from primary systems. Backups age out within ninety days. We can shorten either window in writing on request.
By default, no one. Engineering access is gated on an explicit support ticket from your team, logged, time-limited and reviewed. We do not browse customer data for research, model training, or product analytics.
No. We do not train, fine-tune, or share customer data with third-party AI providers. Any future AI features will be opt-in, school-by-school, with a separate written commitment.
Detected incidents are triaged within four working hours. Confirmed breaches are reported to affected schools within seventy-two hours, with what happened, what we have done, and what you need to do.
Card and UPI details are never stored on our servers. Payments are processed by our PCI-DSS-compliant payment partner (Razorpay) and we receive only tokenized references and settlement metadata.
Yes. Salary visibility is a separate permission from staff management. By default only the principal and the payroll role can see salary figures; everyone else sees the staff directory without the compensation column.

Security review for your IT team.

For deeper review by your IT or compliance team, the Nexadium team can schedule a working session and share documentation under NDA.