Security & privacy

Built to protect student & institution data

Multi-tenant architecture, secure payments, and access controls designed for education institutions.

Platform security

Security built into every layer

From student login to payment processing — your data stays isolated, encrypted, and under your control.

Tenant isolation

Each college runs on its own subdomain with data scoped to that institution. Students and staff never cross tenants.

Encrypted sessions

Staff and student sessions use secure tokens. Passwords are hashed with industry-standard algorithms.

OTP student login

Students verify mobile numbers with one-time passwords — reducing fake accounts and improving traceability.

Secure payments

Fees are processed through Razorpay. Card and UPI details never touch Entrio360 servers.

Role-based access

Institution admins and agents get appropriate permissions. Platform super-admins are separate from college staff.

HTTPS & hosting

Production deployments should use TLS everywhere. Subdomain routing resolves tenants safely per request.

Data practices

How we handle your data

What we store

Student profiles, application form data, uploaded documents, payment records (amounts and gateway references), and support ticket messages.

What we don't store

Full payment card numbers or UPI PINs — Payment Gateway handles payment credentials. Institutions configure their own Payment Gateway keys.

Your responsibilities

Institutions should use strong staff passwords, keep Payment Gateway secrets confidential, and comply with local data protection rules when publishing privacy notices to applicants.

Read our Privacy Policy for more detail.

Questions about security?

We're happy to discuss architecture and compliance with your IT team.