Security & Trust
Last updated: July 23, 2026
This page is maintained by EDUNEST pvt.Ltd to describe the security practices and controls we apply to EDUNEST. It reflects the current security posture of the platform and is not an independent certification or audit report.
Security is a shared responsibility. While we operate the platform and protect the underlying infrastructure, each school is responsible for managing its users, roles, and data-access decisions within EDUNEST.
1. Platform and hosting
EDUNEST is built and hosted on Lovable Cloud, which provides the database, authentication, server functions, and backend infrastructure. Lovable Cloud manages the underlying infrastructure, including patching, availability, and platform-level security controls.
EDUNEST pvt.Ltd is responsible for the application-layer configuration, access policies, and data-handling logic that sits on top of the platform.
- Security contact: officialedunest@gmail.com
- Phone: +91 98837 19024
- Location: Bengaluru, India
2. Encryption
- In transit: All communication between users, the app, and the backend uses HTTPS/TLS.
- At rest: Data is stored in the cloud database with encryption at rest provided by the underlying hosting platform.
- Passwords: User passwords are never stored in plain text. They are hashed using industry-standard algorithms.
3. Authentication and access control
EDUNEST supports secure authentication for schools, teachers, parents, and students:
- Email and password authentication with secure session handling.
- Google sign-in support for convenient and secure access.
- Role-based access controls within each school account.
- Row-level security policies in the database to restrict data access.
Schools are responsible for assigning appropriate roles, removing access for departed staff, and keeping their user lists current.
4. User roles and permissions
EDUNEST uses role-based permissions to ensure users only see the data they need. Common roles include school administrators, teachers, parents, and students. Administrators can manage roles from within the school dashboard.
We recommend following the principle of least privilege: grant only the minimum permissions needed for each user to perform their role.
5. Data handling and storage
School data is stored in a dedicated backend environment. Each school's data is logically separated through database-level access controls. We do not sell or use school data for advertising.
Backups are maintained to support recovery from accidental deletion or system failure. Backup schedules are managed by the platform provider.
6. Notifications and third-party integrations
EDUNEST uses Twilio for WhatsApp notifications and an email service provider for transactional emails such as demo confirmations and authentication messages. These providers handle message delivery only; they are contractually bound to use data for the purpose of delivering EDUNEST services.
7. Maintenance and updates
We apply security updates and patches to the EDUNEST application as needed. The underlying platform manages infrastructure-level patching. We monitor the platform for issues and respond to security advisories that affect our stack.
8. Incident response
If we become aware of a security incident affecting EDUNEST or school data, we will investigate promptly, take steps to contain and remediate the issue, and notify affected school administrators without undue delay.
To report a security concern or vulnerability, please email us at officialedunest@gmail.com with the subject line "Security".
9. Compliance and certifications
EDUNEST follows security practices aligned with common SaaS and education-sector standards. We do not currently hold third-party security certifications. Any certification claims would require an independent audit and explicit review before being published.
10. Shared responsibilities
Schools that use EDUNEST play a key role in keeping their data safe. We recommend that every school:
- Use strong, unique passwords and enable two-factor authentication where available.
- Regularly review user accounts and deactivate users who no longer need access.
- Assign roles based on job function and avoid sharing administrator credentials.
- Educate staff and parents about phishing and suspicious messages.
- Report unusual activity or security concerns to us promptly.
11. Contact us
If you have questions about security, want to report an issue, or need a copy of our Data Processing Agreement, please contact:
EDUNEST pvt.Ltd
Email: officialedunest@gmail.com
Phone: +91 98837 19024
Location: Bengaluru, India
