Infrastructure

Infrastructure, stated plainly.

SquareCampus runs on Amazon Web Services in Mumbai. This page describes how the platform is designed — and anything it does not answer, we will answer in writing during your evaluation.

Cloud region

AWS Mumbai

Architecture

Multi-AZ design

Residency

India-first posture

Encryption

Transit & at rest

Why managed cloud

Why AWS Mumbai? Why not “own servers”?

Data residency isn't defined by who makes the servers — it's defined by where they physically sit and how access is governed. Choosing AWS Mumbai is an engineering decision.

The “own servers” reality check

In this market, “own servers in India” can mean very different things:

Rented racks in shared co-location facilities

A VPS from a hosting provider, sometimes outside India

A single server in a locked room on consumer hardware

“Own” hardware leased from a local hosting company

None of these are automatically bad — but they are different risk profiles, and an institution deserves to know which one it is buying. The useful move is to ask every vendor, including us, the same infrastructure questions in writing.

The comparison

Managed cloud design vs unspecified “own servers”

What we run, next to the questions worth asking any vendor.

Data residency

SquareCampus · AWS Mumbai

AWS Mumbai (ap-south-1)

The platform is designed to keep institutional data in the AWS Mumbai region, with controls intended to restrict resources to that region.

Typical unspecified claims

“India” (unspecified)

Often vague: an India endpoint can sit in front of infrastructure hosted anywhere.

Ask every vendor: Which region and provider, in writing?

Reliability design

SquareCampus · AWS Mumbai

Multi-AZ architecture

Designed across multiple availability zones so a single facility issue does not take the platform down. Recovery objectives are documented and shared during evaluation.

Typical unspecified claims

Single location

One facility means one point of failure and manual recovery.

Ask every vendor: What is your recovery plan if the building fails?

Physical security

SquareCampus · AWS Mumbai

AWS data centres

AWS facilities carry independent certifications (published by AWS). Our application-level controls are documented separately and shared on request.

Typical unspecified claims

“Secure” (undefined)

Varies widely; sometimes a locked room with no third-party attestation.

Ask every vendor: Can you share any third-party attestation?

Scalability

SquareCampus · AWS Mumbai

Cloud auto-scaling

Capacity scales with admission season and exam-week load without hardware purchases, in the same region.

Typical unspecified claims

Hardware bottleneck

Physical servers must be ordered, shipped, and installed to grow.

Ask every vendor: How do you handle a 10x load spike?

Transparency

SquareCampus · AWS Mumbai

Questions answered in writing

We answer infrastructure questionnaires in writing and share architecture documentation during the security review process.

Typical unspecified claims

Vague claims

“Own servers” without documentation is a marketing line, not an architecture.

Ask every vendor: Will you put your answers in writing?

Design decisions

What this design means for your institution

These are the architectural commitments the platform is built around. The specifics behind each one are documented for security reviews.

Built to stay available

The platform is architected across multiple availability zones in the AWS Mumbai region, so a problem in one facility is designed not to take daily campus operations down.

Backups by design

Automated, encrypted backups are part of the platform design. Backup cadence, retention, and restore procedures are documented and shared during security review.

Encryption as baseline

Data is encrypted in transit and at rest as baseline infrastructure, with access controlled by roles and administrative activity logged.

India residency posture

The deployment is designed to keep institutional data in the AWS Mumbai region, with account-level controls intended to restrict where resources can be created.

Layered network protections

Application servers are designed to sit behind managed network protections rather than being directly exposed to the internet.

Documentation on request

Architecture summaries, data-flow documentation, and questionnaire responses are available to evaluating institutions through the security review process.

Due diligence

Questions worth asking every vendor — including us

Use these during your evaluation and compare the answers in writing.

Infrastructure FAQ

The technical questions, answered plainly

Infrastructure review

Ask us the hard questions.

Bring your security questionnaire, your IT committee, or your auditor. We answer infrastructure questions in writing as part of every serious evaluation.