Skip to content
Xavellus

Security & data protection

Sealed by
design

Institutions hand us attendance, fees, payroll, and student records — the most sensitive data they hold. This page sets out plainly how it is separated, protected, and returned.

How separation works

One platform, never one pool of data.

One workspace per institution

Every institution runs at its own address with its own users, branding, and records. Tenant identity is bound to the signed-in session and checked on every request, so a user of one institution cannot reach another’s data — there is no shared screen, list, or report.

Roles decide what loads

Access is enforced on the server, not hidden in the interface. A faculty member, a head of department, a registrar, and a parent each receive only the records their role owns, and actions that require an approval route through one.

Encrypted in transit

All traffic runs over HTTPS. Sign-in uses session cookies that exist to keep you signed in and are never used for advertising or cross-site tracking.

Backups and recovery

The database is backed up on a managed schedule with point-in-time recovery, so an accidental deletion or a bad import can be rolled back rather than rebuilt by hand.

Who can see what

Your records stay yours.

Records inside a workspace belong to the institution that created them. We process them on the institution's behalf to run and support the service — never to train anything, sell anything, or advertise. Access inside our team is limited to what operating and supporting the platform actually requires, and support work happens with the institution's knowledge.

Indian data protection (DPDP Act 2023)

For records inside a workspace, the institution is the data fiduciary and we act as its data processor. Features that collect anything sensitive are off by default and require a documented purpose and notice before they can be switched on — employee monitoring, for example, ships with a consent template and per-department scope control rather than a silent toggle. Requests from students, parents, or staff to see or correct their own data go to their institution first, since the institution controls it.

Getting your data out

Your data is exportable while you are with us — most modules export to Excel or PDF directly — and on termination it is returned or deleted as your agreement sets out. There is no lock-in clause that holds records hostage at renewal.

Reporting something

If you believe you have found a vulnerability or a data issue, email xavellus.pvt@gmail.com with the details. We acknowledge within 2 working days, and we will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.

Questions from your IT committee?

We answer security questionnaires and will walk your team through the architecture, hosting, and backup arrangements before you commit to anything.