Trust & security

You are trusting us with records about children.

This page is written for the person doing your procurement review, not for a marketing brochure. It describes what is actually enforced, where it is enforced, and what we deliberately chose not to do.

The rule that matters most

Hiding a menu item is not access control. Every role and school boundary in Infoleen is enforced server-side — in database security rules, in storage rules, and again inside each server function — independently of what the interface shows. If somebody opens a browser console and issues a request the interface would never send, the request is still refused, because the interface was never the thing refusing it.

We learned this the hard way and then fixed it properly. An audit found controls that lived only in the browser; they are now three-layer, and a test suite exists specifically to stop that class of mistake coming back.

A teacher cannot read another school's data with the developer tools open. That is not a promise about our UI — it is a property of the database.

What's enforced

Controls in place today

Each of these is implemented and covered by automated tests that assert both that the wrong access is refused and that ordinary access still works.

Three-layer access control

Database rules, file-storage rules, and a check inside every callable server function. A gap in any one layer does not open the door on its own.

Strict tenant isolation

Users reach data only for schools they belong to. In a multi-campus group, one campus administrator cannot read a sibling campus unless you explicitly grant it.

A real account kill switch

Blocking an account denies it at the database, disables the sign-in account itself, and revokes its live sessions. It is not a hidden menu — the person is out.

A public surface of exactly three functions

Every server function requires an authenticated caller and re-checks their role and school — except the three behind QuizNova, which by design serve people with no account. Those reach no student record unless the player is a verified pupil of that school, return no answer key, and are rate limited. What they can and cannot do.

Least privilege on self-service

A user editing their own profile can change a short allow-list of their own fields. Nobody escalates their own role or moves themselves into another school.

Layered gating on sensitive areas

High-sensitivity modules such as the warehouse are gated in three independent layers, so a mistake in any one of them does not expose data.

Encrypted in transit and at rest

All traffic over TLS. Data encrypted at rest by the underlying cloud platform, with managed, monitored backups.

Output escaping throughout

User-supplied content is escaped before it reaches the page. The whole client surface has been audited for unescaped interpolation, not just the obvious fields.

Server-side cost and abuse limits

Rate limits on sensitive operations, length caps on free-text fields, and per-school monthly quotas on AI generation — enforced on the server, not the form.

The one public door

What QuizNova can and cannot do.

A teacher can open a six-digit code on a quiz. Anyone who types it into QuizNova answers the questions with no account at all, under a name they choose. It is the only part of Infoleen a person can use without signing in, so it is worth setting out exactly how far it reaches.

What this means for a procurement review: the public surface is two pages and three functions, and the data it collects contains no child's identity unless that child was already a verified pupil of yours. Everything else on the platform still refuses an unauthenticated caller outright.

The question every parent committee asks

Does our students' data go to an AI?

No. This is worth being precise about, because the honest answer is unusual.

AI Studio drafts question papers, rubrics and lesson plans. To do that it sends the AI provider a short description of what to write about — nothing more:

A generated draft comes back, is checked, and is stored in your question bank. Your bank remains your school's asset. We do not use your data to train any model, and we do not permit our providers to either.

Schools without AI Studio send nothing at all. AI Studio is on the Premium tier. If your school is on Standard, no part of your data ever reaches an AI provider, because the feature that would send it is not running.

Children

We do not profile the children who use this.

Most of the people signed in to Infoleen on any given morning are minors. India's Digital Personal Data Protection Act 2023 restricts behavioural profiling and tracking-based advertising directed at under-18s, and we treat that as a design constraint rather than a compliance checkbox.

How we know it holds

The rules are tested, not asserted.

Access control is the kind of thing that quietly breaks. Ours is covered by an automated suite of 177 assertions across database, realtime-database and file-storage rules — account status, cross-tenant isolation, privilege escalation, plan self-upgrade, forged marks and scores, enumeration of certificates, free-text size caps, server-only collections, and QuizNova's public boundary in both directions.

Every assertion checks both directions: that the disallowed request is refused, and that the legitimate one still succeeds. A change that over-tightens and locks out a librarian fails the suite exactly like a change that opens a hole. The suite runs before any change to the rules reaches production.

Security work on the platform is continuous, and we periodically re-audit the whole surface rather than only the parts we changed.

Your data

Yours to take, yours to delete.

Data residency. Region matters, and requirements differ by country and by school. Tell us your requirement during procurement and we will confirm in writing what we can commit to for your specific deployment — rather than have you make a compliance decision based on a marketing page.

Procurement questions

Can we get a data processing agreement?

Yes. Ask during procurement and we will provide one for your legal review, alongside our current list of sub-processors and what each one does. For school data, your school is the controller and Infoleen is the processor acting on your instructions.

Do you train AI models on our data?

No, and our providers are not permitted to either. Separately, the only thing AI Studio sends out is curriculum metadata — subject, grade, chapter, difficulty. No student record ever forms part of a prompt. See the section above.

Who at Infoleen can see our data?

Access is limited to the small number of people who need it to operate and support the platform. Support access to a live school is for the purpose of resolving your request, and we would rather you asked us this question than assumed an answer — put it in writing during procurement and we will answer it in writing.

What happens if there is a breach?

We have a defined response: contain the affected account immediately using the kill switch, assess scope from sign-in records, rotate credentials, and notify. We will tell you what happened, what was affected and what we did, on a timeline that meets the notification obligations that apply to your jurisdiction. We will not discover it from you.

Is the platform penetration tested by a third party?

We run structured internal audits with an automated rules test suite as the backstop, and we re-audit the full surface periodically. If your procurement requires an independent third-party assessment, raise it with us early and we will discuss scope and timing rather than claim something we have not done.

Can a student see another student's marks?

No. A student reads their own record; a guardian reads the records of children they are linked to; a teacher reads the classes they teach. Each of those is a database rule, and each has an assertion in the test suite proving the others are refused.

What happens to accounts when students graduate?

Graduating and leaving students are archived, which both denies database access and disables the sign-in account. This is deliberate: every live ex-student account is another way in. Public certificate verification still works for alumni, so a former student can prove a qualification without retaining a login. Individual accounts can be reactivated by your administrator when there is a genuine need.

Where can we read your privacy terms?

Our privacy policy sets out what we process, our sub-processors, retention and your rights. If something in it is unclear for your jurisdiction, write to contact@infoleen.in and we will clarify in writing.

Send us your security questionnaire.

We would rather answer forty questions before you sign than one after something goes wrong.