Maintained by the Campus OS team

Trust Center

An honest, single-page view of the controls Campus OS operates, the frameworks we map to, and how to reach our security and privacy teams.

This page is maintained by the Campus OS team to answer common security and privacy questions about the platform. It is not a third-party certification.

Encryption at rest

AES-256 across all managed Postgres storage and object buckets.

Encryption in transit

TLS 1.3 on every connection. HSTS and modern cipher suites enforced.

Immutable audit log

Every insert, update and delete on 14 entity types is recorded with actor, old and new snapshots.

Role-based access

Roles stored in a dedicated table with SECURITY DEFINER checks. No client-side role storage.

Multi-tenant isolation

Row-level security on every table scopes data to the institution and the user's role.

Backups & recovery

Continuous backups with point-in-time recovery. Daily snapshots retained per region.

Global compliance

Mapped to every major framework we operate in

Readiness here means the platform supports the policies, data-subject workflows and audit requirements of the listed framework. Your institution remains the controller and is responsible for ongoing operational compliance.

RegionFrameworkPlatform status
United KingdomUK GDPR + DPA 2018Ready
European UnionGDPRReady
United StatesFERPA & COPPA alignedReady
AustraliaPrivacy Act / APPReady
CanadaPIPEDAReady
IndiaDPDP Act 2023Ready
New ZealandPrivacy Act 2020Ready
SingaporePDPAReady
UAE (Dubai)PDPLReady
PhilippinesData Privacy Act 2012Ready
South AfricaPOPIAReady
IrelandGDPRReady

Security contact

Report a vulnerability or incident.

security@campusos.app

Privacy contact

Data-subject requests, DPO escalations.

privacy@campusos.appOpen request form

Compliance contact

Audits, DPIAs and questionnaires.

compliance@campusos.app

Need a deeper review?

Our team can run through architecture, RLS policies, audit logging and incident-response playbooks with your DPO or security lead.