Classfold · Vinidra Infotech Pvt. Ltd.
Security
This page is a product documentation draft for transparency. It is not legal advice. Have qualified counsel review it before you rely on it for compliance or contracting.
This page describes how Vinidra Infotech Pvt. Ltd. approaches security for Classfold. It is an overview for customers and prospects, not a certification, guarantee, or substitute for a signed security schedule or questionnaire response.
Security principles
Classfold is built as a multi-tenant education platform. Our security work focuses on protecting customer data confidentiality, preserving integrity of academic and administrative records, and keeping the service available for legitimate users.
We design controls in layers: secure software development practices, infrastructure hardening, identity and access management, tenant isolation in application logic, encryption in transit, monitoring, and operational response processes.
Security is a shared responsibility. Vinidra secures the platform and underlying environment we operate; customers configure roles inside their tenants, manage their users’ credentials, and control what data they choose to store in Classfold.
This page does not claim third-party certifications or audit attestations. When formal assurance documents are available for a given engagement, they are provided through the commercial or security review process—not by implication from marketing copy.
Product and technical controls
Traffic between clients and Classfold is protected with TLS in transit. We require modern transport security for production endpoints and discourage insecure cleartext access to authenticated product surfaces.
User sessions rely on authenticated access controls. Accounts are protected by credential verification, and product authorization checks gate actions based on the signed-in user’s role and permissions within the relevant tenant context.
Classfold uses a shared-database multi-tenant architecture with tenant-scoped access patterns. Application queries and middleware are designed so that one tenant’s workspace data is not exposed to another tenant under normal operation. Cross-tenant probing or access attempts violate our Terms of Service and are treated as abuse.
Administrative and privileged operations are limited to authorized personnel and service accounts with least-privilege intent. Production access is constrained and reviewed as part of operational practice.
We apply secure development habits including code review for material changes, dependency awareness, and environment separation between development and production where practical. No single control is perfect; we improve controls over time as the product and threat landscape evolve.
- TLS encryption for data in transit
- Authenticated sessions and role-based authorization
- Tenant-scoped access in multi-tenant architecture
- Least-privilege operational access intent
- Ongoing hardening and monitoring of production services
Organizational practices
People with access to production systems or customer data are expected to follow internal acceptable-use and confidentiality expectations. Access is granted based on job need rather than by default to all staff.
We maintain operational runbooks for common reliability and security events, and we favor change management that reduces the chance of accidental exposure or prolonged outage.
Vendors that process data on our behalf are selected with security and privacy considerations in mind and are bound by contractual terms appropriate to their role. Categories of subprocessors are described under infrastructure below.
Security awareness is part of how we operate engineering and support. Training depth varies by role; privileged roles receive stronger expectations around handling credentials and customer information.
Security incidents
We treat suspected security incidents seriously. Our process is designed to detect, contain, investigate, and remediate issues that could affect confidentiality, integrity, or availability of Classfold or customer data.
If a personal data breach affecting customers occurs, we will notify affected customers and, where required, regulators without undue delay, consistent with applicable law and our contractual commitments. We do not promise a fixed universal clock such as a guaranteed hour count for every scenario, because investigation scope and legal duties can vary.
Customers who suspect unauthorized access to their tenant should contact support@classfold.com immediately, reset affected credentials, and preserve relevant logs or screenshots that may help investigation.
Incident communications will typically describe what happened at a high level, what data categories may be involved when known, steps we are taking, and recommended customer actions—without disclosing details that would help attackers.
Responsible disclosure
We welcome good-faith reports of security vulnerabilities in Classfold from researchers and customers. Please email support@classfold.com with a clear description of the issue, steps to reproduce, potential impact, and your contact details.
Do not access or modify other customers’ data, disrupt service availability, or use social engineering against our staff or customers while testing. Limit testing to your own accounts or expressly authorized environments.
We will acknowledge valid reports in a reasonable time and work to validate and remediate confirmed issues. Public disclosure should wait until we have had a reasonable opportunity to investigate and fix the problem, unless a coordinated disclosure timeline is agreed in writing.
Reports submitted in good faith and within these rules help protect institutes and learners who rely on Classfold. Thank you for helping keep the platform safer.
Infrastructure and subprocessors
Classfold runs on cloud infrastructure and depends on specialized service providers for functions we do not operate entirely in-house. Subprocessors act on our instructions under contractual safeguards.
Typical categories include cloud hosting and compute, managed databases and object storage, email and transactional notification delivery, payment processing, error and performance monitoring, and analytics used to understand product health.
We do not list every vendor name on this page because the stack can change as we improve reliability and cost efficiency. Customers with a legitimate need for a current subprocessor list for risk assessment may request it through support@classfold.com as part of a security or procurement review.
Data residency and region choices, where offered, are described in product or commercial documentation for the relevant plan. Default hosting locations follow our standard production topology.
- Cloud hosting and infrastructure
- Data storage and backup services
- Email and notification delivery
- Payment service providers
- Monitoring, logging, and analytics tools