Security & trust
Security your board can stand behind.
Institutions run their most sensitive operations on trueniti — admissions, fees, exams, health and safety. Here is how we protect that data.
How we protect data
Layered security, by design.
Encryption everywhere
Data is encrypted in transit and at rest, so records are protected both on the wire and on disk.
Strict tenant isolation
Every institution's data is walled off from every other. One tenant can never see another's records.
Role-based access
Users see only what their role allows. Students and parents never see staff data or the staff-only chat.
Tamper-evident audit
Sensitive actions are logged to a tamper-evident audit trail, with a full record-of-processing register.
Privacy by design
Consent records, right-to-erasure, a 30-day data-request window and a 72-hour breach process — GDPR & DPDP ready.
Multi-region hosting
Built to run in the region appropriate to each institution, with resilient, backed-up infrastructure.
Your data is yours
We never sell your data, and we never use your institution's data to train AI models. AI features are clearly labelled, optional, and always leave the final decision to a human.
Hosting & sub-processors
trueniti runs on reputable cloud infrastructure, engaged as sub-processors under contract. Our hosting regions and the current sub-processor list are available to customers on request. [FOUNDER: confirm hosting provider(s), regions & where the sub-processor list is published].
Compliance & evidence
The platform is built to support institutional compliance: GDPR and India's DPDP Act, consent and record-of-processing tooling, and SOC 2-style evidence your auditors can use. [FOUNDER: confirm current certification status / SOC 2 report availability].
Incident response
We maintain a documented incident-response process with a 72-hour breach-notification target to affected controllers, in line with GDPR and DPDP expectations.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, please email security@trueniti.com with details and steps to reproduce, and give us a reasonable time to investigate before any public disclosure. [FOUNDER: confirm security contact & responsible-disclosure policy URL].