Built for trust, and for the DPDP Act
A school’s data is a child’s data. Vidyom is engineered so money can’t drift, one school can never see another, student data never trains an AI, and personal data is handled the way India’s Digital Personal Data Protection Act requires - ahead of the 2027 enforcement deadline.
Fail-closed isolation
One school can never see another
Every request runs in a session scoped to a single school. The row-level-security boundary is fail-closed - your own data is admitted, another school’s returns nothing - and every admitted action is sealed into an append-only, tamper-evident audit trail.
Fail-closed tenant isolation
Every school’s data is isolated with row-level security that defaults to denying access. One school can never see another’s data.
Append-only money & audit
Money and sensitive actions are written to append-only, tamper-evident trails - the books and the audit log replay to any moment.
Dual-clock breach response
A suspected data breach opens a statutory incident that runs two clocks in parallel - CERT-In (6 hours) and the Data Protection Board (72 hours) - with a conservative fail-safe scope and an immutable evidence timeline.
Role-based access control
Every privileged action - especially money writes - is gated by roles, enforced server-side and checked in CI.
No student PII to third-party AI
AI features are grounded and human-gated; student personal data is never sent to a third-party large-language model.
Encryption & data residency
Sensitive fields are encrypted; data is hosted in India and isolated per school.
Verifiable parental consent
For under-18 records, the consenting adult is verified (identity / age data or a DigiLocker token) and the linkage is retained as evidence.
Hardened transport
HTTP Strict Transport Security is on by default, with HMAC request signing and mutual-TLS available for the machine and mobile planes.
DPDP, phased to 2027
Built for the obligations before they bite
India’s Digital Personal Data Protection Act and its Rules phase in through 2027. Vidyom already handles the operative duties - consent, data-principal rights, breach clocks - so nothing has to be retrofitted under a deadline.
13 Nov 2025 - DPDP Rules notified
The DPDP Rules 2025 are notified and the phase-in begins; the Data Protection Board is constituted.
~Nov 2026 - Consent managers
Consent-manager registration provisions come into force.
13 May 2027 - Obligations take effect
Notice, consent, security safeguards, breach reporting, retention and data-principal rights become operative.
Is your school ready for 2027?
Take the 8-question DPDP readiness self-assessment and get a prioritised gap report.
Access, correct, erase
Every right, honoured on a clock
Parents and staff exercise their rights and the school honours them promptly - access, correction and erasure on a 30-day target we set (the DPDP Rules fix no statutory deadline for rights requests), and grievances within the 90-day ceiling the Rules allow.
Breach, two clocks
Two timers start the moment we know
On a personal-data breach, two clocks run concurrently to different recipients - CERT-In in 6 hours and the Data Protection Board in 72.
CERT-In - 6 hours
A technical / forensic report to CERT-In within six hours of becoming aware.
DPDP Board - 72 hours
Notify affected data principals without delay, then a detailed report to the Data Protection Board within seventy-two hours. As a processor, Vidyom alerts the school promptly so it can meet its own clocks.
See our privacy policy for the full detail. This page is informational, not legal advice.