Back

Trust is part of the product

Boundaries before
feature theatre.

Institute software handles student, staff, academic and money records. We explain the current controls and current limitations without inventing certifications or calling a future integration live.

Tenant resolution fails closed

An unknown institution host does not fall back to shared institutional data. The request is refused when the tenant cannot be resolved.

Roles do not grant themselves

Owner, Admin, Teacher and Student experiences are driven by the authenticated role returned by the system. Selecting a login tab does not create permission.

Important writes remain accountable

Administrative and institutional changes are designed with identified actors and audit records where the workflow requires attribution.

Credentials have a lifecycle

Issued access can be rotated or revoked and active sessions can be invalidated when staff access changes or a security concern is reported.

Transport is encrypted

Supported public web traffic uses HTTPS/TLS. Passwords are stored as one-way hashes rather than readable text.

Privacy has a named route

Data-protection and deletion requests go to privacy@smarthisaab.in. Security reports use a separate address.

Infrastructure transparency

Who helps deliver
the service.

Vercel delivers the web applications, Render runs the backend application, Neon provides the PostgreSQL database in Singapore, and Meta's WhatsApp Business Platform delivers authorised messages where enabled.

Web

Vercel

Public web delivery and application hosting for the SmartHisaab interfaces.

Application & data

Render + Neon

Backend application hosting and the PostgreSQL data layer used by the service.

Communication

Meta WhatsApp

Recipient number and authorised message content are processed to deliver supported WhatsApp messages.

Payment boundary

PhonePe checkout is not live. PhonePe is the selected future provider for online payments, subject to merchant approval, final privacy and sub-processor disclosures, a production callback host and an approved institution settlement model.

Today, SmartHisaab records payments made through an institution's own methods. Student and guardian fees belong to the institution. The SmartHisaab software subscription is a separate payment the institution makes to Swayam Digital Systems.

No invented assurance

We do not claim a certification, guaranteed uptime, PCI scope, penetration-test status or bug-bounty programme that has not been established. This page describes implemented product boundaries and documented operational practices—not a substitute for a customer's own compliance assessment.

Read the Privacy Policy, Terms of Service, or use the Security Report route for a suspected vulnerability.