Trust and security

Security is the campus nervous system. It has to stay calm under load.

SquareCampus treats trust as part of the product. Access control, India-aware hosting posture, auditability, and operational reliability are built into how institutions run on the system every day.

Audit timeline

Synthetic data

Control domains

The trust posture is designed for institutional accountability

Security is not a decorative trust page. It is the control layer that lets schools and colleges rely on the platform for real operational work.

India-aware hosting posture

SquareCampus is built with an India-first operational posture around hosting, institutional trust, and jurisdictional clarity.

Access control and identity

Role-based access, administrative boundaries, and least-privilege expectations are part of how the product is structured.

Encryption and transport security

Data protection in transit and at rest is treated as baseline product infrastructure, not optional hardening.

Auditability and traceability

Institutional operators need to understand who changed what, when, and in which operational context.

Operational reliability

Uptime, backups, alerting, and recovery posture matter because the platform is part of daily campus operations.

Incident readiness

A credible security posture includes how issues are monitored, handled, communicated, and learned from.

Identity and access

Your identity environment remains yours

The identity provider establishes who a person is. SquareCampus decides what that person may do: institution membership, campus scope, roles, workflow privileges, record access and operational permissions are governed inside SquareCampus and are never derived from an email address or domain alone.

All plans

SquareCampus-managed sign-in

Every plan includes SquareCampus-managed credentials with role-based access. Privileged roles are designed to carry additional sign-in verification, applied according to the institution's policy.

From Pro

Institutional single sign-on

Pro adds optional single sign-on with Microsoft Entra ID for the institution's own tenant, subject to technical onboarding. Staff sign in with their existing institutional accounts under the institution's own MFA, Conditional Access and user-assignment policies, and SquareCampus continues to govern authorisation.

Enterprise

Identity governance

Enterprise is differentiated by identity governance rather than by having SSO. Identity requirements across several campuses or directories, directory-group to role mappings, SSO enforcement policy, joiner-mover-leaver lifecycle controls, identity migration and identity audit controls are scoped as Enterprise requirements during technical discovery.

Your Microsoft environment

Stays under your administration

  1. Your administrator approves SquareCampus in your Microsoft Entra ID tenant.
  2. Staff sign in with their existing institutional Microsoft accounts.
  3. Your MFA, Conditional Access and user-assignment policies continue to apply.

SquareCampus authorisation

Governed inside the School OS

  1. SquareCampus validates that the sign-in came from your approved tenant.
  2. It resolves the person's institution membership and campus scope.
  3. It applies role, record and workflow permissions defined in SquareCampus.
  4. A secure SquareCampus session is issued.
Optional from Pro

Microsoft Entra ID verifies who the user is. SquareCampus determines what the user may access and perform. Single sign-on is chosen by the institution, never required.

Sign-in modes the institution chooses between

  1. Mode 1SquareCampus-managed credentials only
  2. Mode 2SquareCampus credentials alongside institutional single sign-on
  3. Mode 3Institution-enforced single sign-on, where the institution's policy requires it and the configuration supports it
  • Single sign-on is optional. An institution is not required to adopt it, and is not required to move between Google Workspace and Microsoft to use SquareCampus.
  • Standard sign-in authenticates identity only. It does not require access to email, files, Teams, SharePoint or other Microsoft 365 data.
  • Single sign-on authenticates users; it does not create or remove them. Automated provisioning and deprovisioning are a lifecycle requirement scoped under Enterprise.
  • Where institution-enforced single sign-on is configured, SquareCampus credentials are designed not to act as an ordinary alternative route around the institution's identity policy.

Why this matters

The security story is really an operations story

Institutions trust software when it remains understandable, controllable, and accountable during the moments that matter.

Institutional realities

Security should support institutional calm on pressure days, not just satisfy a procurement checklist.
Role-based access matters because real institutions span trustees, principals, finance teams, teachers, operators, parents, and students.
Audit-ready operations matter because education institutions are accountable to boards, regulators, families, and internal leadership.
India-aware posture matters because data trust and operational context are not abstract concerns in this category.
Trust posture summary
Controls are part of the School OS, not isolated to a security appendix.
Monitoring and reliability matter because the product supports daily campus motion.
Audit trails and role boundaries matter because institutional accountability is not optional.

Security questions

What review teams ask first

Where is data hosted?

SquareCampus is designed with an India-first hosting posture. Hosting details and data-flow documentation are shared during the security review process.

How is data encrypted?

Data is encrypted in transit and at rest as part of the platform's baseline design. Implementation details are available under the security review process.

Who can access data?

Access is role-based and least-privileged by design, with administrative access logged and traceable.

Do you support vendor security questionnaires?

Yes. We provide questionnaire support and can share security documentation and summaries on request.

Can an institution use normal SquareCampus credentials?

Yes. Every plan includes SquareCampus-managed credentials with role-based access. Privileged roles are designed to carry additional sign-in verification, applied according to the institution's policy.

Can staff sign in with our own Microsoft accounts?

From Pro, yes. Pro adds optional single sign-on with Microsoft Entra ID for the institution's own tenant, subject to technical onboarding. Staff sign in with their existing institutional accounts under the institution's own MFA, Conditional Access and user-assignment policies, and SquareCampus continues to govern authorisation.

What identity options does Enterprise add?

Enterprise is differentiated by identity governance rather than by having SSO. Identity requirements across several campuses or directories, directory-group to role mappings, SSO enforcement policy, joiner-mover-leaver lifecycle controls, identity migration and identity audit controls are scoped as Enterprise requirements during technical discovery.

Who decides what a signed-in user may do?

The identity provider establishes who a person is. SquareCampus decides what that person may do: institution membership, campus scope, roles, workflow privileges, record access and operational permissions are governed inside SquareCampus and are never derived from an email address or domain alone.

Security review

Bring your questionnaire, policy concerns, or institutional requirements.

The right trust conversation covers the real product controls, the operating posture, and how the institution can stay confident after go-live.