Security

Educational institutions trust CampusMint with sensitive student and financial data. We take that responsibility seriously with industry-standard security practices at every layer.

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Database connections use encrypted channels.

Multi-Tenant Isolation

Each institution's data is logically isolated at the database level. No institution can access another institution's data under any circumstance.

Regular Backups

Automated daily backups with point-in-time recovery capability. Backups are stored in geographically separate locations.

Role-Based Access Control

Granular permissions ensure each user — administrator, teacher, accountant, parent, or student — only accesses what they need.

Audit Logs

Every significant action is logged with timestamps and user attribution. Administrators can review who did what and when.

Data Protection

We follow data minimization principles. Only necessary data is collected, and institutions retain full ownership of their data.

Infrastructure

CampusMint runs on cloud infrastructure with high availability and redundancy. Our servers are hosted in secure data centers with physical access controls, network monitoring, and DDoS protection.

Application Security

All API endpoints are authenticated and authorized. Input validation, parameterized queries, and rate limiting protect against common attack vectors. Sessions are managed with secure, HTTP-only tokens.

Incident Response

We maintain an incident response plan with defined procedures for identifying, containing, and resolving security events. Affected institutions are notified promptly in the event of any data breach.

Questions about security?

If you have specific security requirements or questions about our practices, contact us at security@campusmint.app.