Security & data protection

How CoursePilot protects campus schedules, grades, and attendance

Clear controls for university buyers — tenant isolation, encrypted transport, roles, hashed passwords, export, backups, and incident handling — aligned with our Privacy Policy and Data Processing Notice under RA 10173.

Tenant isolation

Each institution operates within its own university and campus workspace. Offerings, enrollments, attendance, grades, and related records are scoped so one subscriber’s data is not mixed into another institution’s view.

Encrypted connections

Production application traffic is served over HTTPS/TLS so credentials and academic data are not sent in clear text between the browser and CoursePilot.

Role-based access

Students, instructors, campus administrators, and platform operators receive different permissions. Class records and grades are released only through authorized workflows; students see their own released results.

Password security

Passwords are stored as one-way bcrypt hashes — never as plain text — so a database copy alone does not expose login secrets.

Data export

Institutions can export academic and operational records while the workspace is active (for example course offerings and faculty workload reports). During subscription wind-down, export remains available so campuses can keep a local copy.

Backups

Production data runs on a managed PostgreSQL host. Automated database backups and restore capability are provided by that host as part of our production operations. Exact backup frequency and retention follow the host’s policy for our plan; we can restore from those restore points if the live database is lost or corrupted.

Incident response

Report suspected security or privacy incidents to support@apmexitsolutions.com, including the campus or university name, when you noticed the issue, and what you observed. If a personal data breach affects a subscriber’s workspace, we notify that subscriber without undue delay so the campus can meet its obligations under the Philippine Data Privacy Act (RA 10173). We then contain the issue, assess tenant impact, remediate, and document follow-up with the affected institution.

Legal backing

These practices support the commitments in our legal documents: encrypted transport and hashed passwords; retention while the subscription is active plus a wind-down window; breach notification to the subscriber without undue delay; and return or deletion of subscriber data after the agreed retention period.

Privacy Policy · Data Processing Notice · Terms of Service

Security or privacy questions: support@apmexitsolutions.com