Trust & Security

Your students' data, protected — by design.

A business school runs on trust. This page explains, in plain language, exactly how Aula Magna safeguards the personal data of your students, faculty and alumni — in transit, at rest, and every day in between.

Encryption everywhere

TLS 1.2+ in transit (HSTS, preloaded) and AES-256 at rest. Data is never stored or transmitted in the clear.

Least-privilege access

Role-based access enforced in middleware before any page loads — students see only their own records. Multi-factor authentication available for staff and admin accounts, plus single sign-on through your institution's identity provider.

Full audit trail

Every meaningful action on personal data is logged with who, what and when — reviewable and exportable for your compliance team.

Backups & resilience

Automated, encrypted backups with point-in-time recovery, a documented backup & disaster-recovery plan, and a scheduled restore-test drill. A backup we've never restored is not a backup.

GDPR-first

EU data residency, a signed Data Processing Agreement, data minimisation, right to erasure, and 72-hour breach notification.

Hardened by default

Content-Security-Policy, clickjacking + MIME-sniffing protections, rate limiting, and automated dependency, static-analysis and secret scanning on every change.

Security is a program, not a promise

"Never breached" is not a one-time state — it's a set of things we run on a schedule, forever. This is the cadence behind the platform.

Every commit
Automated dependency scanning + static analysis + tests; high-severity findings block release.
Weekly
Dependency patching and review of authentication / access logs for anomalies.
Monthly
A backup-restore test, an access review (who can reach production data), and a secret-rotation check.
Quarterly
Vulnerability scanning, a disaster-recovery drill, and a review of our subprocessors.
Annually
An access recertification and an incident-response exercise.
Continuously
24/7 uptime, error and security monitoring, with automated encrypted backups.

Data governance & GDPR

  • Your school is the Data Controller; Aula Magna acts strictly as your Data Processor under a signed DPA (GDPR Art. 28).
  • EU data residency — your data is hosted in the region you require.
  • Data minimisation — we collect only what the platform needs to function.
  • Right to access, correction and erasure, handled within statutory timelines.
  • Personal-data breach notification within 72 hours, with a documented response runbook.
  • A named Data Protection Officer you can reach directly.

Wrap, don't rip out

Aula Magna is designed to sit alongside your existing systems, not replace them. Your student system-of-record stays where it is and under your control — which means adopting Aula Magna does not create a risky data migration or a second copy of everything.

Subprocessors

We use a small, vetted set of infrastructure providers, each of which encrypts data at rest and maintains their own recognised certifications:

  • Vercel — application hosting & edge network (EU region)SOC 2
  • Neon — managed Postgres database (EU · Frankfurt)SOC 2 · ISO 27001

See the full subprocessor list and our Data Processing Agreement.

Certifications & roadmap

We believe in claiming only what is true. Today, the platform runs the encryption, access-control, monitoring and GDPR practices described above, with automated dependency, static-analysis and secret scanning on every change. An independent third-party penetration test is scheduled before our first institutional deployment, and we are working toward formal ISO 27001 (with SOC 2 Type II to follow) — happy to share our current status and roadmap, and our security document pack, under NDA.

Found a vulnerability?

We welcome responsible disclosure. Email security@aulamagna.io with details and we'll acknowledge within 2 business days. Please give us reasonable time to remediate before any public disclosure.

This overview describes the security posture of a production Aula Magna deployment. Specifics can be tailored to your institution's requirements — contact security@aulamagna.io. Last updated · 9 July 2026.