[ Institutional Information Security ]

Security & Isolation

Institutional architecture documentation on multi-tenant cryptographic isolation, TLS 1.3/AES-256 encryption, Indian cloud data sovereignty, and disaster recovery.

Framework: SOC 2 Type II / ISO 27001 Aligned•Residency: Mumbai Cloud Region (ap-south-1)•Audit: CERT-In Empanelled VAPT

1. Multi-Tenant Logical Database Isolation

TeachMentorAI employs enterprise-grade Row-Level Security (RLS) and isolated cryptographic tenant keys to guarantee complete separation of school institutional records:

Zero Cross-Tenant Leakage

Every database query, API transaction, and search index requires an immutable, signed cryptographic Tenant ID (`school_id`). Queries cannot cross institution boundary barriers under any condition.

Schema-Level Enforcement

Enforcement occurs at the database execution layer, preventing human error, API bugs, or compromised user tokens from exposing data belonging to another campus.

2. Cryptographic Encryption Standards

In-Transit EncryptionTLS 1.3 / HSTS

All HTTP REST endpoints, WebSocket connections for real-time bus tracking, and mobile sync packets are transmitted over TLS 1.3 with Perfect Forward Secrecy (PFS) and 4096-bit RSA certificate pinning.

At-Rest EncryptionAES-256 GCM

All relational database volumes, backup archives, document uploads (CBSE marks sheets, birth certificates), and database WAL logs are encrypted using hardware-accelerated AES-256 encryption managed via cloud Key Management Services (KMS).

3. Indian Cloud Data Sovereignty

Pursuant to India’s Digital Personal Data Protection (DPDP) Act 2023 and educational regulatory frameworks:

  • 100% of primary production databases, replica nodes, and cloud storage volumes are physically hosted in certified data centers within the Republic of India (Mumbai/Hyderabad zones).
  • No student personally identifiable information (PII) or assessment records are ever mirrored, transferred, or processed outside sovereign Indian borders without statutory authorization.

4. Android Device Security & Offline Sync Protection

The TeachMentorAI Android mobile application operates on a zero-trust model designed specifically for school devices and faculty smartphones:

Encrypted Local SQLite

Offline records stored during broadband outages are encrypted using device-hardware keys via the Android Keystore System.

Zero Adware & Zero Trackers

The application binary contains zero analytics surveillance SDKs, commercial ad banners, or third-party telemetry collectors.

5. Automated Backups & Disaster Recovery (DR)

To safeguard institutional continuity across academic cycles, examination sessions, and annual admissions:

< 15 min

Point-In-Time Recovery

Continuous WAL write streaming prevents data loss during infrastructure incidents.

Daily

Encrypted Snapshots

Immutable full cluster snapshots stored in geographically isolated secondary Indian zones.

< 4 Hours

Recovery Time Objective

Automated failover clustering guarantees swift restoration of operations.

6. Access Governance & Immutable Audit Logs

Educational institutions maintain stringent oversight over who views and edits student records:

  • Immutable Audit Trails: Every critical transaction—including mark modifications, fee receipts, concession waivers, and student promotion rollbacks—is logged with timestamp, user ID, IP address, and changed values.
  • Privileged Access Restrictions: TeachMentorAI platform engineers possess zero default access to institutional databases. Temporary diagnostic access requires just-in-time cryptographic approval and is logged in full.

7. Vulnerability Management & CERT-In Compliance

TeachMentorAI maintains compliance with cybersecurity directives issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act, 2000.

Security Operations & Incident Escalation

Security researchers or institutional IT teams encountering potential vulnerabilities are requested to notify our designated security team at security@teachmentorai.in or corporate compliance at hello@w3builders.com. All credible reports receive acknowledgement within 24 hours.