Version 1.0Updated: August 2026

Data Protection & Security

This page describes the security measures and data protection practices implemented in the Real Public School management platform.

Legal Compliance Disclaimer

This page describes security practices for informational purposes. It does not constitute certification of compliance with GDPR, DPDP Act, ISO 27001, PCI-DSS, or any other specific standard or regulation. Compliance with applicable regulations should be verified with qualified technical and legal professionals.

Security Measures Overview

The following security measures are implemented in the Real Public School management platform.

Implemented

Authentication & Password Security

Secure user authentication with encrypted credential storage.

  • Passwords stored using cryptographic hashing (bcrypt/argon2)
  • Plain-text passwords never stored or logged
  • Password reset handled by school administration with identity verification
  • Session token expiry enforced
Planned

Role-Based Access Control (RBAC)

Access to data is restricted based on user roles.

  • Student, Teacher, Parent, Admin roles with distinct permissions
  • Students access only their own records
  • Teachers access only assigned class data
  • Admins have controlled administrative access
Implemented

Secure API Communication

All data transmitted between client and server is encrypted.

  • HTTPS/TLS encryption for all API calls
  • Authentication tokens required for protected endpoints
  • Input validation and sanitization on all endpoints
  • CORS policy restricting unauthorized origins
Implemented

Database Security

Database access is restricted and credentials are protected.

  • Database credentials never exposed in frontend code
  • Service-role keys restricted to server-side only
  • Parameterized queries to prevent SQL injection
  • Row-level security policies on sensitive tables
Implemented

Secure File Access

Uploaded files accessible only through authorized access controls.

  • Files not publicly accessible via direct URL
  • Access mediated through platform authorization layer
  • File type validation on upload
Planned

Audit Logging

Administrative actions may be logged for accountability.

  • Logging of key administrative actions is planned
  • Audit log implementation depends on platform configuration
Implemented

Session Management

User sessions are managed securely to prevent hijacking.

  • Session tokens expire after period of inactivity
  • Logout invalidates the session server-side
  • Secure, HttpOnly cookies used for session storage
Implemented

Infrastructure & Hosting

Platform hosted on cloud infrastructure with standard security controls.

  • Cloud hosting with environment separation (production vs development)
  • Regular dependency and security updates applied
  • Secure environment variable management
Planned

Backup & Recovery

Data backup and recovery procedures.

  • Backup configuration depends on the hosting provider and school setup
  • Recovery procedures are subject to the school's operational configuration
Implemented

Error Handling & Logging

Errors are handled securely without exposing sensitive information.

  • Error messages do not expose internal system details to end users
  • Server-side error logging for debugging and monitoring
  • Stack traces not displayed in production environment
  • Rate limiting on sensitive endpoints (e.g., login)
Planned

Payment Data Security

Sensitive payment credentials are not stored by the school.

  • Raw card numbers, CVV, UPI PINs not stored by the school
  • Payment processing, where enabled, is delegated to a third-party payment gateway
  • Only transaction reference and status are stored by the school
Planned

Data Encryption at Rest

Encryption of stored data depends on the hosting infrastructure.

  • Encryption at rest depends on the cloud provider and hosting configuration
  • Sensitive fields (tokens, secrets) are managed at the application level

Security Practices Checklist

HTTPS enforced on all pages and API endpoints
Passwords hashed — never stored in plain text
Role-based access control implemented
Student data not publicly accessible
Payment credentials not stored by school
Session expiry implemented
Input validation on all form fields
Error messages do not expose system internals
Database row-level security policies

Responsible Disclosure

If you discover a security vulnerability in the Real Public School management platform, we ask that you report it responsibly:

  • Report the vulnerability to the school administrator immediately
  • Do not exploit, further investigate, or disclose the vulnerability to others
  • Provide enough information for the technical team to reproduce and address the issue
  • Allow a reasonable time for the vulnerability to be addressed before any public disclosure

Security reports: tbgaming796@gmail.com