Skip to main content
Enterprise Security

Your Data isSafe With Us

Industry-leading security measures protect your school's data at every layer.

01

Data Security

Your data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted and stored in geographically distributed locations.

3 protections

End-to-End Encryption

All sensitive data is encrypted using industry-standard AES-256 encryption.

Automated Backups

Daily encrypted backups with point-in-time recovery and 30-day retention.

Data Residency

Choose where your data is stored to comply with local regulations.

02

Authentication & Access

Multi-factor authentication, SSO integration, and session management keep unauthorized users out.

3 protections

Multi-Factor Authentication

TOTP-based MFA for all administrative accounts with backup recovery codes.

Single Sign-On

SAML 2.0 and OIDC integration with Google Workspace, Microsoft 365, and more.

Session Management

Configurable session timeouts, device tracking, and remote session termination.

03

Infrastructure

Enterprise-grade cloud infrastructure with automated scaling, monitoring, and 99.9% uptime SLA.

3 protections

99.9% Uptime SLA

Redundant infrastructure with automated failover across multiple availability zones.

24/7 Monitoring

Real-time application and infrastructure monitoring with instant alerting.

DDoS Protection

Multi-layer DDoS mitigation with global CDN and rate limiting.

04

Compliance by Design

Built from the ground up to help schools meet data protection regulations across the EU and MENA region.

4 protections

GDPR-Ready

Built-in data portability, right to erasure, and consent management to help schools meet EU data protection requirements.

FERPA-Aligned

Student education records are protected with role-based access controls and audit logging aligned with FERPA principles.

Data Governance

Configurable data retention policies, audit trails, and access controls designed for regulatory compliance.

Regional Compliance

Designed to meet data protection requirements across the EU and MENA, with data residency options and privacy-first architecture.

Our Security Commitment

We treat your school's data with the same care you treat your students. Security isn't an afterthought — it's built into every layer of our platform, from architecture to operations.

Every security implementation is reviewed by multiple AI models — providing independent, thorough analysis that catches what manual review might miss.

Questions About Security?

Our security team is happy to discuss our practices in detail.

Security Questions

Common questions about how we protect your school's data.

Where is my school's data stored?

Data is hosted on managed infrastructure with strict tenant isolation at the database level. Each school's data is logically separated and cannot be accessed by another school under any circumstance.

Is Tawaasal GDPR-compliant?

Yes. We support configurable data retention policies, audit trails for deleted records, Data Subject Access Requests (DSAR), right-to-erasure, and compliance reporting. School admins can manage retention and DSARs directly from the Data Retention panel.

Data rights and privacy: https://tawaasal.com/en/data-rights

How are user passwords and accounts protected?

Passwords are hashed with industry-standard algorithms — never stored in plain text. We also support multi-factor authentication (TOTP and SMS), recovery codes, optional single sign-on, reCAPTCHA on sensitive endpoints, and social login on supported tiers.

Can I require multi-factor authentication for admins?

Yes. MFA can be enabled at the tenant level and required for specific roles such as school admins. Each user can set up MFA with an authenticator app, SMS codes, and recovery codes.

Are backups taken automatically?

Yes. Production databases are backed up on a regular schedule with point-in-time recovery available. Backups are encrypted at rest and retained according to our published policy.

Who can see student records inside the school?

Access is permission-based and scoped by role. Teachers see only their own classes; guardians see only their linked children; admins see their own school. All sensitive access is logged in the audit trail and can be reviewed by the school admin at any time.

Can I export my data if we decide to leave?

Yes. You can export all your school's data at any time using the Data Export tools — in XLSX, JSON, or PDF for reports. We follow GDPR rules for deletion of remaining data after export, with a clear timeline communicated to you.

Data rights and export: https://tawaasal.com/en/data-rights

What can an AI assistant read from our school?

Only the categories your school admin allows, from: attendance, grades, merit points, timetables, the school calendar, and standard reports. Within those, an assistant sees exactly what the person who connected it sees — ask about a pupil outside your classes and it will tell you that pupil isn't visible to you rather than answering.

Safeguarding concerns, wellbeing records and private messages are excluded from connectors entirely, on every plan.

Connections are read-only, expire after 90 days, and end after 7 days unused. Anyone can disconnect from their profile; a school admin can revoke any connection.

Where does our data go when someone uses an AI assistant?

The question asked and the answer returned are sent to the assistant's provider — OpenAI, Anthropic or Google, depending on which is connected. Once it leaves Tawaasal we no longer control it, including how long they keep it, and some personal accounts on those services may use conversations to improve their models. Treat it as you would treat pasting the same information into that assistant by hand, because that is what it is.

Your school can decline connectors entirely, or require multi-factor authentication before anyone connects.