Every student record, every exam result, every parent payment — protected by the same engineering standards used by Nigerian fintechs.
Six pillars
Every record carries a tenant_id. Row-level security on every query. Cross-tenant data leakage is architecturally impossible.
AES-256 encryption at rest. TLS 1.3 in transit with modern ciphers, HSTS, and HTTP/3.
Short-lived access tokens (15 min) + rotating refresh tokens. Tokens revoked instantly on logout.
Every privileged action is logged with actor, target, IP, and timestamp. Logs are append-only.
Admin, teacher, student, parent — each with fine-grained, principle-of-least-privilege permissions.
Data resident in Nigeria via MainOne data centers. No cross-border data transfer by default.
Compliance
Nigerian Data Protection Regulation
Full compliance with NITDA's data protection framework — registered as a Data Controller.
General Data Protection Regulation
EU-aligned data handling for schools serving international students.
Information Security Management
In active certification. Audited annually by a third party.
Payment Card Industry Data Security
Card data never touches our servers — handled by Paystack (Level 1 certified).
Operational practices
30-day retention. Restorable to any point in the last 7 days.
24/7 on-call rotation. 4-hour SLA on critical issues.
Quarterly external pentest by a CREST-certified firm.
Cloudflare in front of every endpoint with bot management.
You own everything you put into EduPro. We're custodians — never owners.
Found a security issue? We pay bounties from ₦50k to ₦2M depending on severity.
security@edupro.ng →