Security
Educational institutions trust CampusMint with sensitive student and financial data. We take that responsibility seriously with industry-standard security practices at every layer.
Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Database connections use encrypted channels.
Multi-Tenant Isolation
Each institution's data is logically isolated at the database level. No institution can access another institution's data under any circumstance.
Regular Backups
Automated daily backups with point-in-time recovery capability. Backups are stored in geographically separate locations.
Role-Based Access Control
Granular permissions ensure each user — administrator, teacher, accountant, parent, or student — only accesses what they need.
Audit Logs
Every significant action is logged with timestamps and user attribution. Administrators can review who did what and when.
Data Protection
We follow data minimization principles. Only necessary data is collected, and institutions retain full ownership of their data.
Infrastructure
CampusMint runs on cloud infrastructure with high availability and redundancy. Our servers are hosted in secure data centers with physical access controls, network monitoring, and DDoS protection.
Application Security
All API endpoints are authenticated and authorized. Input validation, parameterized queries, and rate limiting protect against common attack vectors. Sessions are managed with secure, HTTP-only tokens.
Incident Response
We maintain an incident response plan with defined procedures for identifying, containing, and resolving security events. Affected institutions are notified promptly in the event of any data breach.
Questions about security?
If you have specific security requirements or questions about our practices, contact us at security@campusmint.app.