ClassegyAcademic OS
Bank-Grade Infrastructure

Enterprise Security & Tenant Isolation Architecture

How Classegy safeguards sensitive academic records, financial transactions, and student biometrics for high-volume campuses and multi-branch networks.

PostgreSQL Tenant Isolation

Every school tenant is isolated using strict schema partitioning and Row-Level Security (RLS). Cross-tenant queries are blocked at the database engine level.

AES-256 & TLS 1.3 Encryption

All stored records, report cards, and fee ledgers are encrypted at rest using AES-256. Web and mobile communications are strictly enforced with TLS 1.3.

Granular Dynamic RBAC

Define custom permissions for over 15+ campus roles (Super Admin, Principal, Accountant, Warden, Teacher, Parent). Session tokens expire dynamically with MFA support.

Data Sovereignty & Infrastructure Freedom

You Decide Where Your School Data Lives

Classegy gives educational trusts and school boards complete autonomy over data residency, infrastructure hosting, and database ownership. Everything from your student records to fee receipts and attachments belongs 100% to you.

Option 1: Managed Cloud

Classegy Managed Cloud

Turnkey, zero-DevOps deployment. Managed high-availability infrastructure with automatic backups, geo-redundancy, continuous security patching, and 99.9% uptime SLA.

  • Zero server management required
  • Automated hourly backups & snapshots
  • Instant provisioning for new terms
Best for standalone schools & fast launches
Option 2: Dedicated VPC

Dedicated Regional VPC

An isolated cloud cluster provisioned exclusively for your school network in your jurisdiction of choice (India, UAE, Saudi Arabia, Europe, US, or Singapore).

  • Guaranteed in-country data residency
  • Physically isolated compute & storage
  • Custom domain & dedicated IP
Best for regional multi-campus trusts
Option 3: School Private Cloud (BYOC)

Your Own Infrastructure

Run Classegy with the database and object storage residing directly inside your institution's private AWS, Azure, GCP, or on-premise servers.

  • 100% database & file storage ownership
  • You hold master KMS encryption keys
  • Direct read-replica access for internal BI
Best for enterprise trusts with strict IT mandates
Complete Data Ownership

You own all student profiles, fee transaction ledgers, grades, biometric hashes, and document attachments. We never monetize, analyze, or claim rights to your institution's data.

Zero Vendor Lock-In

Export complete relational database dumps and file archives anytime with a single click or automated API sync. If you ever leave, your data remains fully intact in standard formats.

Custom KMS Key Isolation

Enterprise campuses can bring their own Customer-Managed Encryption Keys (CMEK). Even infrastructure administrators cannot decrypt your student files without your authorized key.

Infrastructure & Disaster Recovery Benchmarks

Comparing Classegy modern cloud architecture against legacy school ERP servers

Security ParameterClassegy Cloud StandardLegacy On-Premise / Monolith
Backup FrequencyAutomated hourly snapshots + geo-replicationManual weekly dumps on physical hard drives
Tenant Data SeparationDatabase Row-Level Security (RLS) schemasShared tables with vulnerable single-column IDs
Recovery Time Objective (RTO)< 15 minutes automated failover24 to 72 hours manual server reboot
Biometric Template StorageOne-way SHA-256 irreversible hashes onlyUnencrypted raw image files on local PC

Request Institutional Security Whitepaper & SOC2 Brief

Our infrastructure engineering team can provide your IT committee with complete architecture diagrams and compliance certificates.