Amatya

Security

An institute's records are its business. Amatya's security model starts at the architecture, not at a checkbox.

One database per institute

Every institute runs in its own isolated database — not a shared table with a tenant column. Cross-institute access is impossible by construction, and a franchise's centres are additionally scoped inside it.

Role-based access

Owners, centre managers and staff each see exactly what their role allows — per module, per action, per centre. Permissions apply without re-login when revoked.

Backups

Nightly, per-institute backups. Your data is also yours to export at any time.

Verifiable certificates, private records

Certificate QR verification pages expose only what the certificate states — never the student's wider record.

Reporting a vulnerability

Found something? Tell us via the contact page — we read security reports first and respond fast.