SOC 2 Type II Certified

Security & Compliance

Your data security is our top priority. Here's how we protect your school's information.

Security Overview

At Scholaris, security isn't an afterthought, it's built into every layer of our platform. We understand that schools entrust us with sensitive student data, financial information, and personal details. That's why we've implemented enterprise-grade security measures that meet and exceed industry standards.

Our security program is continuously monitored, tested, and improved to protect against evolving threats while maintaining the ease of use that makes Scholaris accessible to everyone.

Certifications & Compliance

๐Ÿ”’

SOC 2 Type II

Independently audited and certified for security, availability, processing integrity, confidentiality, and privacy.

๐ŸŒ

GDPR Ready

Compliant with international data protection regulations including GDPR and local Nigerian data protection laws.

๐ŸŽ“

FERPA Compliant

Meets requirements for protecting student education records and personally identifiable information.

โœ…

ISO 27001 Aligned

Our information security management system follows ISO 27001 best practices and standards.

Infrastructure Security

โ˜๏ธCloud Infrastructure

Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA. Our servers are distributed across multiple availability zones for redundancy and disaster recovery.

๐Ÿ”Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Database encryption keys are rotated regularly and managed through secure key management systems.

๐Ÿ›ก๏ธNetwork Security

Protected by enterprise firewalls, DDoS mitigation, intrusion detection systems, and regular vulnerability scanning. All network traffic is monitored 24/7.

๐Ÿ’พBackups

Automated daily backups with point-in-time recovery. Backups are encrypted, geographically distributed, and tested regularly to ensure data can be restored quickly.

Application Security

๐Ÿ”‘Authentication & Authorization

Multi-factor authentication (MFA) available for all accounts. Role-based access control (RBAC) ensures users only see data relevant to their role.

  • Password requirements enforce strong credentials
  • Session management with automatic timeout
  • Single sign-on (SSO) support for enterprise customers

๐Ÿ”Security Testing

Continuous security testing throughout the development lifecycle:

  • Automated vulnerability scanning on every code commit
  • Annual third-party penetration testing
  • Regular security audits and code reviews
  • Bug bounty program for responsible disclosure

๐Ÿ“ŠMonitoring & Logging

Comprehensive logging of all system activities with real-time monitoring and alerting. Security events are analyzed using advanced threat detection systems. Logs are retained for compliance and forensic analysis.

Data Privacy & Control

Data Ownership

You own your data. We never sell or share your data with third parties for marketing purposes. You can export your data at any time in standard formats.

Data Residency

Data is stored in secure data centers with options for regional data residency to comply with local regulations. Nigerian schools can choose to have their data stored exclusively within Nigeria.

Data Deletion

When you delete data or close your account, we permanently delete your information within 30 days, except where retention is required by law.

Organizational Security

Employee Access

Strict access controls limit employee access to customer data. All employees undergo background checks and security training. Access is logged and regularly audited.

Security Training

All team members complete security awareness training during onboarding and annually thereafter. We maintain a security-first culture across the organization.

Incident Response

We maintain a comprehensive incident response plan with 24/7 security monitoring. In the unlikely event of a security incident, we follow established protocols to contain, investigate, and remediate issues while keeping affected customers informed.

Third-Party Security

We carefully vet all third-party vendors and service providers to ensure they meet our security standards:

  • All vendors undergo security assessments before integration
  • Vendors must maintain appropriate security certifications
  • Data processing agreements are in place with all vendors
  • Regular reviews ensure ongoing compliance with our standards

Transparency & Communication

We believe in transparency about our security practices:

  • Security updates and advisories are published promptly
  • System status and uptime are publicly available
  • We maintain open communication channels for security concerns
  • Annual security reports are available to enterprise customers

Report a Security Issue:

Email: security@scholaris.com

We respond to security reports within 24 hours.