Security Policy
Last updated:
1. Overview
Mobiskul is committed to protecting the confidentiality, integrity, and availability of customer data. This Security Policy summarizes the practices we apply across the platform. It is provided for transparency and does not constitute a contractual commitment.
2. Data Encryption
Data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard encryption (AES-256). Backups are encrypted, and cryptographic keys are managed through a dedicated secrets management system with restricted access.
3. Access Controls
We enforce role-based access control (RBAC), principle of least privilege, and per-school tenant isolation at the database level. Multi-factor authentication (MFA) is available and recommended for all administrative accounts. Access to production systems is logged and reviewed.
4. Infrastructure Security
The Services run on hardened cloud infrastructure with network segmentation, Web Application Firewall (WAF), DDoS protection, and automated patching. We monitor availability and performance continuously and maintain backups with tested recovery procedures.
5. Monitoring and Logging
Security-relevant events are logged and monitored for anomalies. Audit logs capture administrative actions to support accountability and incident investigation.
6. Vulnerability Disclosure Policy
We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability, please report it privately to security@mobiskul.com. Do not disclose the issue publicly until it has been resolved. We will acknowledge reports promptly and work to remediate verified issues.
7. Bug Bounty Program
We operate a coordinated disclosure process and may offer recognition or rewards for qualifying reports at our discretion. Reports that comply with this policy will not be subject to legal action.
8. Incident Response
We maintain an incident response process for detection, containment, eradication, and recovery. Where a personal data breach occurs, we notify affected customers and regulators as required under the GDPR and applicable laws.
9. Testing and Assessments
We perform regular vulnerability scanning, dependency reviews, and periodic penetration testing by qualified assessors. Findings are tracked to remediation through our security process.
10. Compliance and Certifications
Our practices align with recognized frameworks including ISO/IEC 27001 principles, OWASP guidance, and applicable data protection law. Customers with specific compliance needs should contact us for current attestations.
11. Contact
Security reports and questions: security@mobiskul.com.