Security
Security Policy
Effective Date: October 10, 2026
Last Updated: October 10, 2026
1. Our Commitment to Security
At Nisaab360, we believe that educational technology should be built on trust, reliability, and responsible information protection.
Our platform helps schools and colleges manage academic records, student information, attendance, examinations, fees, and institutional operations.
We recognize that this information requires careful protection, particularly when it involves children, parents, teachers, and educational institutions.
Security is an important consideration in how Nisaab360 is developed, operated, and maintained.
This Security Policy outlines our approach to platform protection, institutional responsibilities, vulnerability reporting, and the responsible handling of security concerns.
2. Scope of This Policy
This policy applies to the Nisaab360 website, online Learning Management System, and associated digital services operated by Nisaab360.
Official Website: https://nisaab360.app
The policy addresses security responsibilities related to user accounts, institutional data, authorized platform access, technical operations, and vulnerability reporting.
Third-party systems and services that Nisaab360 does not operate are not automatically covered by this policy.
3. Institutional Data Protection
Educational institutions retain ownership of the information they submit to Nisaab360, as established in the applicable Institutional Agreement.
This may include student records, employee details, parent information, attendance records, examination results, and financial administration records.
Nisaab360 is designed as a multi-tenant platform, supporting institution-specific environments and permission-based access.
The objective of these architectural controls is to prevent unauthorized access to records belonging to other institutions.
Institutions are responsible for maintaining appropriate account permissions and ensuring that information is accessed only for legitimate educational and administrative purposes.
4. Authentication and Access Control
Nisaab360 uses an account-based access model designed to distinguish between different institutional roles.
These roles may include institutional owners, administrators, teachers, employees, students, and parents.
Access to administrative functions and institutional information is intended to be governed by assigned permissions.
Users must access the platform only through accounts they are authorized to use.
Unauthorized attempts to bypass authentication, elevate privileges, impersonate other users, or access another institution's information are prohibited.
Institutions are responsible for managing the accounts and permissions of their authorized users.
5. Account Security Responsibilities
Users are responsible for taking reasonable precautions to protect their accounts.
Users should create strong, unique passwords, avoid reusing credentials across unrelated services, and keep authentication information confidential.
Credentials must not be shared with unauthorized individuals.
Users should avoid signing in on untrusted devices and should report suspected account compromise as soon as possible.
Institutions should review user permissions when employees change roles or leave the organization.
If you believe your Nisaab360 account has been compromised, contact [email protected].
6. Application and Infrastructure Security
Nisaab360 recognizes the importance of protecting its application, supporting infrastructure, and stored institutional information.
Relevant security considerations include secure authentication, authorization, input validation, controlled file handling, dependency maintenance, network protection, and appropriate access restrictions.
Security controls should be reviewed as the platform evolves and new functionality is introduced.
Changes affecting authentication, institutional boundaries, financial records, or personal information warrant particular attention.
This policy does not represent that every potential vulnerability has been eliminated or that the platform has undergone a particular external security certification.
7. Data Confidentiality
Institutional information must be handled in accordance with the applicable Institutional Agreement, Privacy Policy, and legal obligations.
Users must not disclose confidential institutional information to unauthorized third parties.
Nisaab360 and its subscribing institutions are subject to the confidentiality responsibilities established in their contractual arrangements.
Confidentiality obligations apply to information exchanged through the platform and other authorized communications.
8. Security Monitoring and Incident Handling
Security-related events may require investigation to determine their nature, potential impact, and appropriate response.
Where suspicious activity, unauthorized access, or a potential security incident is identified, appropriate steps should be taken to assess the situation and protect affected systems or information.
Depending on the circumstances, these steps may include restricting compromised access, investigating relevant records, correcting vulnerabilities, and coordinating with affected institutions.
Any notification obligations are determined by applicable law and contractual requirements.
Users and institutions should promptly report suspected security incidents through the official technical support channel.
9. Reporting a Security Vulnerability
We welcome responsible reports concerning potential security weaknesses affecting Nisaab360.
If you discover a suspected vulnerability, please report it privately rather than sharing details publicly.
Security Reporting Email: [email protected]
A useful vulnerability report should describe the affected service, the observed issue, its potential impact, and the steps needed to reproduce it using authorized accounts and non-sensitive information.
Screenshots or technical details may be included where they do not expose personal information, credentials, or confidential institutional records.
Please do not send passwords, session tokens, private keys, or actual student records in vulnerability reports.
10. Responsible Vulnerability Disclosure
Nisaab360 encourages security concerns to be reported responsibly.
Researchers and users should avoid activities that may compromise the privacy, availability, or integrity of the Services.
The following activities are not authorized without explicit prior written permission:
- Accessing, extracting, modifying, or deleting data belonging to other users or institutions.
- Performing denial-of-service attacks or intentionally disrupting platform availability.
- Conducting large-scale automated scanning or aggressive security testing.
- Exploiting vulnerabilities beyond what is necessary to identify a suspected issue.
- Attempting social engineering, phishing, or credential theft.
- Uploading malware or executing destructive payloads.
- Testing third-party systems that are outside Nisaab360's control.
- Publishing sensitive vulnerability details before appropriate disclosure coordination.
If you encounter personal or confidential information during an authorized activity, stop accessing it and report the issue privately.
A public website or endpoint is not automatically an invitation to conduct penetration testing.
Written authorization is required before performing intrusive security assessments.
11. Vulnerability Review and Remediation
Reported security issues should be evaluated according to their potential impact, reproducibility, severity, and relevance to Nisaab360.
Confirmed vulnerabilities should be assessed for appropriate corrective action.
The time required to investigate or resolve an issue may vary depending on its complexity, operational impact, and available mitigation options.
Nisaab360 does not guarantee a specific remediation deadline through this policy.
Researchers should coordinate any public disclosure with Nisaab360 to reduce the risk of exposing users or institutions to preventable harm.
No financial reward, bug bounty payment, or public recognition is guaranteed for vulnerability reports.
12. Security Testing and Authorization
Security research affecting Nisaab360 infrastructure must comply with applicable laws and the authorization provided by the platform operator.
Permission to use a normal institutional account does not grant permission to conduct penetration tests, exploit vulnerabilities, or access resources outside that account's authorized scope.
Individuals interested in conducting a security assessment should obtain explicit written authorization before beginning testing.
Authorization may specify the systems, techniques, accounts, time periods, and operational restrictions applicable to the assessment.
Testing beyond an agreed scope is not authorized.
13. Third-Party Dependencies
Nisaab360 may use external software libraries, infrastructure providers, and supporting technical services as part of operating the platform.
The security of these components is relevant to the overall security of the Services.
Security considerations include maintaining supported software versions, assessing known vulnerabilities, and reviewing dependencies where appropriate.
Third-party products and services may have their own security policies and disclosure procedures.
Nisaab360 does not guarantee the independent security of every third-party service outside its control.
14. Service Availability
Nisaab360 operates as an online SaaS platform.
Service availability may be affected by scheduled maintenance, software updates, infrastructure failures, cyberattacks, or circumstances beyond reasonable operational control.
Planned outages will be communicated online in accordance with the Institutional Agreement.
Temporary interruptions do not automatically indicate a security incident.
Any specific service-level obligations are governed by applicable written agreements.
15. Data Exports and Account Termination
Institutions retain ownership of their data and may use supported online export functionality provided by the platform.
Institutions should arrange necessary exports before subscription termination or loss of account access.
Information handling following termination remains subject to the Institutional Agreement, Privacy Policy, and applicable legal requirements.
Account termination does not necessarily result in immediate deletion of all stored records or backups.
Requests concerning account closure, data exports, or information retention may be submitted through the official support channels.
16. Privacy and Regulatory Responsibilities
Nisaab360's processing of personal information is addressed in its Privacy Policy.
Where applicable, relevant data protection requirements must be considered when handling institutional and personal information.
This includes any obligations arising under Pakistani law and, where its territorial scope applies, the European Union's General Data Protection Regulation (GDPR).
The existence of this Security Policy does not constitute a representation that Nisaab360 holds ISO 27001, SOC 2, or other independent security certifications.
No such certification is claimed through this document.
17. Security Responsibilities of Institutions
Institutions play an important role in maintaining the security of their information.
Institutions are responsible for assigning appropriate permissions, managing authorized users, protecting institutional account credentials, and ensuring that the information submitted to the platform is handled lawfully.
Institutional administrators should promptly revoke access that is no longer required.
Users should report suspicious account activity and avoid sharing confidential institutional information through unauthorized communication channels.
Platform security depends on both technical safeguards and responsible use.
18. Changes to This Policy
Nisaab360 may revise this Security Policy as its platform, security practices, operational requirements, or applicable obligations evolve.
The effective date and last updated date will identify the published version.
Material changes affecting contractual responsibilities remain subject to the applicable Institutional Agreement and legal requirements.
19. Contact Information
For security concerns, suspected unauthorized access, vulnerability reports, or technical incidents, contact Nisaab360 through the following official channels.
Security and Technical Support: [email protected]
General Inquiries: [email protected]
Support Days: Monday to Friday
Location: Dunyapur, Lodhran, Pakistan
Official Website: https://nisaab360.app
20. Our Security Commitment
Nisaab360 was founded on August 14, 2026, with a vision to help modernize educational administration in Pakistan.
We believe that digitizing education also brings a responsibility to respect the security and confidentiality of institutional information.
Our objective is to develop technology that institutions can use with confidence while continuing to evaluate and improve how the platform protects its users and their information.
Security is an ongoing responsibility, not a one-time achievement.
Nisaab360
Moving Education Beyond Registers.
https://nisaab360.app