An unknown institution host does not fall back to shared institutional data. The request is refused when the tenant cannot be resolved.
Trust is part of the product
Boundaries before
feature theatre.
Institute software handles student, staff, academic and money records. We explain the current controls and current limitations without inventing certifications or calling a future integration live.
Owner, Admin, Teacher and Student experiences are driven by the authenticated role returned by the system. Selecting a login tab does not create permission.
Administrative and institutional changes are designed with identified actors and audit records where the workflow requires attribution.
Issued access can be rotated or revoked and active sessions can be invalidated when staff access changes or a security concern is reported.
Supported public web traffic uses HTTPS/TLS. Passwords are stored as one-way hashes rather than readable text.
Data-protection and deletion requests go to privacy@smarthisaab.in. Security reports use a separate address.
Infrastructure transparency
Who helps deliver
the service.
Vercel delivers the web applications, Render runs the backend application, Neon provides the PostgreSQL database in Singapore, and Meta's WhatsApp Business Platform delivers authorised messages where enabled.
Vercel
Public web delivery and application hosting for the SmartHisaab interfaces.
Render + Neon
Backend application hosting and the PostgreSQL data layer used by the service.
Meta WhatsApp
Recipient number and authorised message content are processed to deliver supported WhatsApp messages.
Payment boundary
Today, SmartHisaab records payments made through an institution's own methods. Student and guardian fees belong to the institution. The SmartHisaab software subscription is a separate payment the institution makes to Swayam Digital Systems.
No invented assurance
We do not claim a certification, guaranteed uptime, PCI scope, penetration-test status or bug-bounty programme that has not been established. This page describes implemented product boundaries and documented operational practices—not a substitute for a customer's own compliance assessment.
Read the Privacy Policy, Terms of Service, or use the Security Report route for a suspected vulnerability.