Security & Audits | ISMS Core | Durgaai Solutions
Security Centre

Security Audits & Bulletins

Transparency Reports Detailing The Technical Resilience Of The ISMS Infrastructure — Multi-Layer Security, TLS 1.3, JWT Auth & Penetration Testing.

LAST UPDATED : June 2026
STATUS : ALL SYSTEMS NOMINAL
INFRA : DEDICATED SERVERS
ISMS Security Posture: Active All ISMS Core Systems — ERP Admin Portal, Staff App, Parents App — Are Protected By Multi-Layer Security Architecture Including TLS 1.3 Transport, JWT Session Management, Role-Based Access Controls, And Dedicated Server Infrastructure With 99.9% SLA.

Security Sections

01 System Uptime Guarantee

We Do Not Use Cheap Shared Hosting. All ISMS Data Is Routed Through High-Performance Dedicated Servers Customized For Our Code Schemas. We Deliver A Standard 99.9% Uptime SLA For The Core Portal API Arrays Ensuring Fluid Synchronization Between Mobile Apps And The Web Dashboard.

Our Infrastructure Is Provisioned On Dedicated Physical Servers — Not Shared VMs — To Ensure Performance Isolation During High-Load Events Such As Statewide Exam Result Releases Or Annual Fee Collection Cycles.

Service ComponentSLA TargetMonitoring
ERP Admin Portal API99.9% Monthly24/7 Automated Health Checks
Parents App Data Endpoints99.9% MonthlyResponse-Time Probes Every 60s
Staff App REST API99.9% MonthlyJWT Validity + Endpoint Ping
Database Read Cluster99.95% MonthlyReplication Lag Monitoring
School Verification Registry99.9% MonthlyCertificate Status Checks
Dedicated Server Architecture ISMS Runs On Dedicated Bare-Metal Servers With Isolated Network Segments. No Other Tenant Shares Our Compute Or Memory Resources — Eliminating Noisy-Neighbor Performance Degradation During Peak Academic Seasons.

02 Authentication & Access Security

Every Access Point In The ISMS Ecosystem Is Protected By Time-Bounded JSON Web Tokens (JWT). Sessions Are Scoped To Specific Roles And Expire Automatically To Prevent Unauthorized Re-Use Of Stolen Credentials.

03 Cryptographic Transport Protocols

Routine Penetration Testing Sweeps Are Executed Monthly Against Our API Endpoints. At Rest, All Central Databases Employ AES-256 Block Encryption Equivalents. In Transit, Our Android App Endpoints Firmly Reject Any Downgraded HTTP Connections, Mandating Strict TLS 1.3 Handshake Verification Before Transmitting Encrypted JSON App Payloads.

LayerProtocol / AlgorithmImplementation
Transport SecurityTLS 1.3 MandatoryPlain HTTP Connections Rejected With 301 Redirect To HTTPS
At-Rest EncryptionAES-256-GCMDatabase Storage Volumes Encrypted At Block Level
Token SigningHMAC-SHA256 / RS256JWT Access & Refresh Token Pairs
Android Credential StorageEncryptedSharedPreferencesAndroid Keystore-Backed Secure Credential Vault
API Certificate PinningX.509 Certificate ValidationMobile Apps Validate Server Certificate Fingerprint On Connect
Password Hashingbcrypt (cost=12)Adaptive Cost Factor — Computationally Expensive For Brute-Force
Zero Plaintext Policy ISMS Core Has A Strict "Zero Plaintext" Policy. Credentials, Tokens, And Sensitive Academic Records Are Never Serialized Or Logged In Plaintext At Any Layer — Transport, Application, Or Storage.

04 Infrastructure Security

The ISMS Backend Is Containerized Using Docker And Served Behind A Battle-Hardened Nginx Reverse Proxy. Multiple Security Layers Protect The Server Before Any Request Reaches Application Code.

05 Data Isolation Architecture

Every School That Deploys ISMS Core Operates In A Logically Isolated Data Environment. No School Can Access Another School's Records — Isolation Is Enforced At The Database Query Level Via School Code Scoping On Every API Call.

School Data Ownership Durgaai Solutions Acts Purely As The Technology Vendor. All Academic Data (Marks, Fees, Attendance) Belongs Exclusively To The Registered Institution. We Do Not Sell, License, Or Share School Data With Any Third Party.

06 Penetration Testing & Monitoring

ISMS Core Undergoes Regular Security Assessment Cycles To Proactively Identify And Remediate Vulnerabilities Before They Can Be Exploited.

07 Vulnerability Disclosure Program

We Welcome Responsible Security Research And Appreciate Ethical Disclosures From The Security Community. If You Discover A Vulnerability In The ISMS Ecosystem, We Ask That You Follow Our Responsible Disclosure Guidelines.

Report A Vulnerability

Found A Security Issue? Responsible Disclosure Helps Keep Schools Safe. Contact Our Security Team Directly.

security@durgaaisolutions.in

08 Security Bulletins (2026)

This Log Records All Security Events, Patches, And Proactive Hardening Measures Applied To The ISMS Production Environment.

Current Security Status: All Systems Nominal No Active High Or Critical Severity Vulnerabilities Exist In The ISMS Production Environment As Of The Date Of This Bulletin. The Security Team Continues Proactive Monitoring 24/7.

Security & Compliance Contact

For General Security Questions, Compliance Inquiries, Or Responsible Disclosure — Our Team Is Ready To Assist.

security@durgaaisolutions.in