Security

Controls you can check, not badges.

We hold no certifications today, and we are not going to imply otherwise. Here is what is actually true about the architecture — each line verifiable in a demo.

The controls a request passes, and the certifications not heldA request passes four controls. Authentication is email OTP with no password store and one active session per user. Authorisation is server-side on every request, deny by default, with tenant isolation enforced in middleware. Evidence is never exposed by a public URL; it is streamed through the backend under permission checks, and each artifact carries a SHA-256 recorded at capture. Retention is set per account and per data class rather than fixed by us. Below, support access: an Exam Center engineer cannot enter an account unless the institution grants a window, which is time-boxed, expires on its own, and audits every action taken inside it. Beside it, the certifications not held: no SOC 2, no ISO 27001, no CERT-In VAPT and no published SLA.EVERY REQUEST PASSES01Authenticationemail OTPno password storeone active session02Authorisationserver-side, every requestdeny by defaultisolation in middleware03Evidencenever a public URLstreamed under checksSHA-256 at capture04Retentionset per accountand per data classnot fixed by usSupport access is yours to grantWE CANNOT ENTER YOUR ACCOUNT WITHOUT ITyou granta window, explicitlytime-boxedit expires on its ownauditedevery action inside itNo badge for any of itNOT HELD, AND NOT IN PROGRESSSOC 2ISO 27001CERT-In VAPTa published SLAEACH LINE ABOVE IS CHECKABLE IN A DEMO — THAT IS THE POINT OF LISTING THEM
01

No password store

Authentication is email OTP. No passwords are stored anywhere, so there is no password database to breach. One active session per user, enforced platform-wide.

No password storeAuthentication is email OTP. No passwords are stored, so there is no password database to breach. One active session per user is enforced platform-wide.EMAIL A CODEONE SESSION PER USERNo password databaseSO THERE IS NONE TO BREACH
02

Deny by default

Authorisation is server-side on every request, deny by default. Tenant isolation is enforced in middleware, not by developer convention — the difference matters when someone is under deadline pressure.

Deny by default, on the serverEvery request is authorised server-side and denied unless a role explicitly allows it. Tenant isolation is enforced in middleware, not by developer convention.REQUESTMiddlewareTENANT + PERMISSIONAllowedDENIEDDENY IS THE DEFAULTNOT A UI DECISION
03

Evidence handling

Evidence bytes are never exposed by a public URL; they are streamed through the backend under permission checks. Each artifact carries a SHA-256 recorded at capture.

Evidence is never a public linkEvidence bytes are never exposed by a public URL. Every request is streamed through the backend under permission checks.A REQUESTPermission checkROLE AND TENANTSTREAMNO PUBLIC URL
04

Retention you configure

Retention periods are set per account and per data class, not fixed by us.

Retention you configureRetention periods are set per account and per data class, not fixed by the vendor.You set each periodRecordingsEvidenceResultsPER ACCOUNT, PER DATA CLASS
05

Support access is tenant-granted

Our support engineers cannot enter your account unless you grant an explicit window that expires on its own, and every impersonation is audited.

Support access is granted, time-boxed and auditedA platform support engineer cannot enter an account until the institution grants an explicit window. The window expires by itself, and every action inside it is audited.SupportNO ACCESSYou grant a windowIT EXPIRES ON ITS OWNWhile it is openAUDITEDSCOPEDREVOCABLE
06

Where we stand on compliance

No SOC 2, no ISO 27001, no CERT-In VAPT, and no published SLA. We would rather tell you that than let procurement discover it later. If a certification is a hard requirement for your institution, say so early and we will tell you honestly where we are.

Where we stand on complianceNo SOC 2, no ISO 27001, no CERT-In VAPT and no published SLA. The controls listed on this page are real and checkable in a demo.We do not holdSOC 2ISO 27001CERT-IN VAPTA PUBLISHED SLAWe do haveNO PASSWORD STOREDENY BY DEFAULTTENANT ISOLATIONGRANTED SUPPORTCHECK THE RIGHT COLUMN YOURSELF IN A DEMO
01

Accessibility

WCAG 2.2 AA is the target for the candidate-facing exam experience and for this site, and contrast on this site is measured rather than assumed. A full third-party audit has not been carried out. If you have an accessibility requirement for a specific cohort, raise it early and we will tell you plainly whether we meet it today.

Bring one paper. We'll run it live.

Thirty minutes, your own exam, no slide deck.