Trust centre
How CampusConnect protects school data
Schools trust us with information about children, families and staff. This page explains the safeguards built into the platform — only what we can show in our code — and our commitments to you.
At a glance
- Role-based access for every user type
- HTTPS everywhere; bcrypt-hashed passwords
- School data isolation, covered by tests
- OTP sign-in and failed-attempt limits
- Audit log of important actions
- No ads, no data selling, no trackers
Identity & access
Every person signs in to an account made for their role, and sees only what that role allows.
Role-based access
Separate roles for school admins, teachers and staff (including accountants), students and parents, bus drivers, and platform administrators. Each API route checks the caller's role before it runs.
Hashed passwords
Passwords are stored only as bcrypt hashes, never in plain text.
Signed login tokens
Sessions use signed JSON Web Tokens. Changing a school admin's password invalidates tokens issued before the change.
OTP sign-in and verification
Mobile users (students, parents, drivers) can sign in with a one-time code by SMS; platform administrators confirm their login with an e-mailed OTP that expires after 5 minutes.
Limits on failed login and OTP attempts
Repeated failed sign-ins and OTP checks are limited per account (not per network, so one school's shared internet connection doesn't lock everyone out).
School data isolation
Many schools run on the platform; each one's records stay its own.
Tenant isolation, with tests
Requests are scoped to the caller's school: a record that belongs to another school is treated exactly like a record that doesn't exist. Automated tests cover this behaviour.
Real-time channels are scoped too
Live updates (chat and announcements) only join rooms of the user's own school; students only their own class and student rooms.
Reseller and group scoping
Partner and group accounts see only the schools they own, within configurable limits on schools and students.
Data protection
Sensitive values are protected in transit, at rest where it matters most, and in every response.
Encrypted connections
The web app and the mobile apps talk to our servers over HTTPS, with TLS certificates from Let's Encrypt.
Payment gateway keys encrypted at rest
A school's online-payment credentials are stored encrypted (AES-256), and payment status is confirmed with the gateway rather than trusted from the browser.
Secrets never leave in responses
Password hashes and storage keys are stripped from every API response, whichever endpoint returns a user record.
Protection against server-side request forgery
When the platform fetches a user-supplied URL (e.g. an image), connections to internal, private and cloud-metadata addresses are refused — including after redirects.
Accountability
Important actions can be traced back to who did them and when.
Audit log
Important actions are recorded with the user, role, time, IP address and device details, and school admins can review them in the Audit log.
Reversible fee corrections
A wrong receipt is reverted — not silently deleted — and the reversal is kept in the record.
Session-wise records
Each academic year is kept as its own session, so past years stay intact when a new one starts.
- We never sell personal data and never show ads in the apps.
- Schools own the data they put into CampusConnect; we process it on their behalf and instructions.
- This website sets no tracking cookies and loads no third-party trackers.
- Designed with India's Digital Personal Data Protection Act, 2023 (DPDP Act) in mind.
The company behind CampusConnect
IQLEXA Technologies Private Limited
CampusConnect is built and operated by IQLEXA Technologies Private Limited, a registered company in India headquartered in Pune. The certifications below are held by IQLEXA Technologies as a company.
905, Gera Imperium Alpha, Kharadi, Pune 411014, Maharashtra, India
FAQ
Security questions
Need something for a security questionnaire? Email contact@campusconnecthub.com.
Who owns the data a school puts into CampusConnect?
The school. We process it on the school's behalf and instructions to provide the service, as described in our privacy policy.
Can one school see another school's data?
No. Requests are scoped to the signed-in user's school, and a record from another school is treated as if it doesn't exist. Automated tests check this behaviour.
How are passwords stored?
Only as bcrypt hashes. Password hashes and storage keys are removed from every API response.
Is CampusConnect compliant with the DPDP Act?
CampusConnect is designed with India's Digital Personal Data Protection Act, 2023 in mind — schools control their data, access is role-based and important actions are logged. Compliance is a shared responsibility: schools, as data fiduciaries, decide what data they collect and on what basis.
How do I report a security issue?
Email contact@campusconnecthub.com with the details. Please don't share the issue publicly until we've had a chance to fix it.
Get started
Questions about security? Let's talk.
We're happy to walk your IT team or management through how CampusConnect protects your data.
- Personalised demo, at a time that suits you
- Help importing your data from Excel
- Training for admins, accountants and teachers
- +91 95382 22239WhatsApp support
