Data Protection & Security
Last updated: 13 August 2026
This page describes the safeguards built into the GyanOS platform and the topics we document with each institution before production deployment. It is a security overview, not a substitute for an institution-specific data-processing agreement.
Institutional control and access
Access is role- and permission-based, with academic context applied where relevant. Administrative, faculty, student, applicant, and parent experiences are separated so users receive only the access needed for their responsibilities. Sensitive actions are auditable, and supported administrative accounts can use time-based one-time-password two-factor authentication.
Encryption and credentials
Personal signature images are encrypted using AES-256-GCM. Passwords use one-way password hashing, and two-factor backup codes are stored as individual bcrypt hashes rather than plaintext. Production database encryption, transport security, backup handling, and key custody are confirmed in the deployment and contractual documentation for each institution.
Students, parents, and minors
K–12 deployments may process information relating to children and their guardians. Parent access uses explicit parent–student links and scoped child selection. The institution remains responsible for defining the lawful purpose, notices, consent or other authorization required for its deployment and policies.
Retention, deletion, and data export
Operational retention periods, deletion procedures, archival requirements, and export or return of data are agreed with the institution before production use. GyanOS supports structured imports and exports; we do not publish a universal retention period because statutory and institutional requirements differ.
Service providers and hosting
Hosting location, infrastructure providers, email and notification services, payment services, and any other sub-processors depend on the modules and deployment selected by the institution. A current, deployment-specific list can be supplied during procurement rather than presenting a generic list that may not match the proposed environment.
Incident response and DPDP readiness
Security incident contacts, investigation and notification responsibilities, response timeframes, and India’s Digital Personal Data Protection Act, 2023 obligations should be recorded in the customer agreement and data-processing terms. We do not claim statutory certification or blanket compliance on this website; readiness is assessed against the institution’s actual deployment and processing purposes.
Request the security pack
Institutional IT, legal, and procurement teams can request deployment architecture, data-flow details, security controls, retention terms, sub-processor information, and incident-response commitments at hello@gyanos.in.