India-aware hosting posture
SquareCampus is built with an India-first operational posture around hosting, institutional trust, and jurisdictional clarity.
Trust and security
SquareCampus treats trust as part of the product. Access control, India-aware hosting posture, auditability, and operational reliability are built into how institutions run on the system every day.
Audit timeline
Synthetic dataControl domains
Security is not a decorative trust page. It is the control layer that lets schools and colleges rely on the platform for real operational work.
SquareCampus is built with an India-first operational posture around hosting, institutional trust, and jurisdictional clarity.
Role-based access, administrative boundaries, and least-privilege expectations are part of how the product is structured.
Data protection in transit and at rest is treated as baseline product infrastructure, not optional hardening.
Institutional operators need to understand who changed what, when, and in which operational context.
Uptime, backups, alerting, and recovery posture matter because the platform is part of daily campus operations.
A credible security posture includes how issues are monitored, handled, communicated, and learned from.
Identity and access
The identity provider establishes who a person is. SquareCampus decides what that person may do: institution membership, campus scope, roles, workflow privileges, record access and operational permissions are governed inside SquareCampus and are never derived from an email address or domain alone.
All plans
Every plan includes SquareCampus-managed credentials with role-based access. Privileged roles are designed to carry additional sign-in verification, applied according to the institution's policy.
From Pro
Pro adds optional single sign-on with Microsoft Entra ID for the institution's own tenant, subject to technical onboarding. Staff sign in with their existing institutional accounts under the institution's own MFA, Conditional Access and user-assignment policies, and SquareCampus continues to govern authorisation.
Enterprise
Enterprise is differentiated by identity governance rather than by having SSO. Identity requirements across several campuses or directories, directory-group to role mappings, SSO enforcement policy, joiner-mover-leaver lifecycle controls, identity migration and identity audit controls are scoped as Enterprise requirements during technical discovery.
Stays under your administration
Governed inside the School OS
Microsoft Entra ID verifies who the user is. SquareCampus determines what the user may access and perform. Single sign-on is chosen by the institution, never required.
Sign-in modes the institution chooses between
Why this matters
Institutions trust software when it remains understandable, controllable, and accountable during the moments that matter.
Institutional realities
Security questions
SquareCampus is designed with an India-first hosting posture. Hosting details and data-flow documentation are shared during the security review process.
Data is encrypted in transit and at rest as part of the platform's baseline design. Implementation details are available under the security review process.
Access is role-based and least-privileged by design, with administrative access logged and traceable.
Yes. We provide questionnaire support and can share security documentation and summaries on request.
Yes. Every plan includes SquareCampus-managed credentials with role-based access. Privileged roles are designed to carry additional sign-in verification, applied according to the institution's policy.
From Pro, yes. Pro adds optional single sign-on with Microsoft Entra ID for the institution's own tenant, subject to technical onboarding. Staff sign in with their existing institutional accounts under the institution's own MFA, Conditional Access and user-assignment policies, and SquareCampus continues to govern authorisation.
Enterprise is differentiated by identity governance rather than by having SSO. Identity requirements across several campuses or directories, directory-group to role mappings, SSO enforcement policy, joiner-mover-leaver lifecycle controls, identity migration and identity audit controls are scoped as Enterprise requirements during technical discovery.
The identity provider establishes who a person is. SquareCampus decides what that person may do: institution membership, campus scope, roles, workflow privileges, record access and operational permissions are governed inside SquareCampus and are never derived from an email address or domain alone.
Security review
The right trust conversation covers the real product controls, the operating posture, and how the institution can stay confident after go-live.