Built for data you cannot afford to lose.
Schools hand us information about children, families and staff. Here is precisely how it is protected — everything below is shipped, not on a roadmap.
Six things protecting your school's data.
Not a posture statement — the mechanisms, in plain words.
Encrypted in transit and at rest
Every request is served over TLS. The credentials you bring for payment gateways and messaging providers are sealed with AES-256-GCM before they touch the database — they cannot be read out of a backup, including by us.
Role-based access, enforced server-side
Permissions are checked on the server for every request, not hidden in the interface. A clerk who cannot open the fee ledger cannot reach those figures from any screen, export or search box.
One school never sees another
Every query is scoped to your organisation and branch in the data layer, not the UI. Multi-branch groups decide exactly which branch each member of staff can see.
An audit trail you can actually read
Consequential actions — fee collection, concessions, refunds, certificate issue, record changes — are written to an audit log with who did it and when, and surfaced inside the product for your own review.
Two-factor sign-in and lockout
Staff accounts can require a one-time code by email on top of the password, and your admins can enforce it per role. Repeated failed attempts lock the account instead of letting a guesser keep going.
DPDP tooling, not just a promise
The platform ships the machinery the Digital Personal Data Protection Act asks for: a register for data-rights requests, a breach record, retention settings and a named grievance officer.
The habits behind the features.
- Data is hosted in India.
- Backups run on a schedule so records can be restored after an incident.
- We collect only what the platform needs to run — and we do not sell data, to anyone, ever.
- Administrative access on our side is limited to authorised staff on a need-to-know basis.
- Parents and students reach only their own children’s records, through their own sign-in.
- Infrastructure runs on established cloud platforms carrying their own security certifications.
Certifications we have not earned yet.
We are a young company and we will not print a badge we have not been audited for. OningIQ is not currently ISO 27001 or SOC 2 certified. The controls on this page are real and in the product today; formal third-party certification is something we intend to pursue as we grow, and we will say so here on the day it is genuinely true.
If your procurement needs a security questionnaire completed, write to us and a human will answer it honestly — including the questions where the answer is “not yet”.
Send us your questionnaireFound something? Tell us.
If you believe you have found a security issue, email hello@oningmediasolutions.com with the details. We investigate every report, we will not threaten researchers acting in good faith, and we will work with you on responsible disclosure.
Security is shared: use strong, unique passwords, grant staff the least access they need, and remove access the day someone leaves.
Ask us anything about your data
We would rather answer a hard security question before you sign than discover it together afterwards.
On-site walkthrough · Free migration assistance · Onboarding in under 14 days