Trust & compliance
Data security at Skolzo
Factual overview of platform security controls for school owners, IT admins, and compliance reviewers.
How we protect school data
Skolzo is built for Indian schools handling student and parent personal information. We combine tenant isolation, encrypted transport (HTTPS), encrypted integration secrets, role-based access, and immutable audit logs.
Trust center (in-app)
After signup, institution admins on Premium or Enterprise plans can open the trust center in CRM or ERP to review audit events, run access reviews, manage retention policies, and export compliance bundles.
Data subject requests
School admins can log access, correction, and erasure requests with identity verification — supporting DPDP-aligned workflows for leads and students.
What we do not claim
Skolzo does not currently hold SOC 2 or ISO 27001 certification. We do not guarantee India-only data residency unless your deployment contract specifies it.
Security by plan
Tenant isolation
All plans
Each school’s data is scoped by institution. Staff only see records for campuses and roles they are assigned to.
Role-based access & PII masking
All plans
Granular permissions control who can view full contact details. Counselors see masked phone and email unless granted PII access.
Audit trail
All plans
Every call, message, and status change on leads, users, students, and payments is logged for managers and compliance reviews.
Trust center & compliance exports
Premium & Enterprise
Download audit logs, consent records, and data exports for CBSE accreditation or internal access reviews — from the in-app trust center. Includes DPDP data subject request workflow.
Two-factor authentication (TOTP)
All plans (org mandate: Enterprise)
Every staff member can enable authenticator-app MFA on their account. Enterprise plans can require MFA for all admins or all users.
Questions? Contact us or review our privacy policy.

