New Ivake now replies to new enquiries, checks documents and chases unpaid fees on its own. See how it works
Platform
Solutions
Resources

You are holding children's records. We build for that

Marks, fees, health notes, addresses and identity documents belonging to people who cannot consent for themselves. This page is written for the committee that has to sign off on where all of that lives.

Residency and hosting

Your data does not leave India

Production databases, file storage and backups are all in Indian regions. Nothing is replicated to a foreign region for convenience.

Indian regions only

Primary and standby databases, document storage and backup snapshots are hosted in India. The list of regions is in the security documentation shared during evaluation.

Dedicated, if you need it

Groups and universities that require a database of their own, rather than a shared one, can have it. So can institutions whose own policy requires a private deployment.

Named sub-processors

Every third party that touches your data — hosting, payments, messaging — is listed by name and purpose. You are told before that list changes.

Access control

Who can see what, and who looked

Permissions match the org chart

Access is set by campus, department, programme and role. A class teacher sees their sections. A hostel warden sees residents, not marks. Financial and health information is restricted separately from everything else.

Every action is recorded

Create, update, approve, export and every AI action is written to an audit trail with the actor, the timestamp and the previous value. Marks and fee entries keep a full revision history, so a changed grade can always be traced to a person.

Single sign-on and de-provisioning

Google Workspace, Microsoft Entra ID and SAML. Staff accounts are created and closed from your directory, so a departure removes access immediately rather than whenever somebody remembers.

Our own staff access is limited

Support access to a live institution requires a reason, is time-bound, and is logged in the same audit trail you can read. Nobody at Ivake browses your records casually.

Protection and continuity

Encrypted, backed up, and recoverable

In transit and at rest

  • TLS on every connection, including the mobile apps
  • Encrypted storage for documents and database backups
  • Signed URLs with expiry for marksheet and certificate downloads
  • Credentials hashed, never recoverable in plain text

Backups and recovery

  • Automated daily backups, retained on a defined schedule
  • Point-in-time recovery within the retention window
  • Restores are tested, not assumed
  • Backups encrypted and held in the same Indian region

Keeping it standing

  • Standby database with automatic failover
  • Monitoring and alerting on availability and errors
  • Rate limiting and abuse protection on public endpoints
  • Release notes and advance notice for planned maintenance

Indian data protection law

Built for the DPDP Act, and for children's data

Under the Digital Personal Data Protection Act 2023 your institution is the Data Fiduciary and Ivake is a Data Processor acting on your instructions. The obligations are yours; our job is to make meeting them practical.

Consent you can evidence

Notice and consent are captured at the point a parent or applicant submits data, with the purpose recorded alongside it. Withdrawal is recorded the same way. When a regulator or a parent asks what was agreed and when, the answer is in the record rather than in somebody's memory.

Children are treated as children

The Act sets a higher bar for anyone under eighteen, including verifiable parental consent and a prohibition on behavioural tracking and targeted advertising. Ivake does no advertising, no behavioural profiling and no ad-tech tracking of students. There is nothing to switch off.

Rights requests

Access, correction and erasure requests can be answered from one student record rather than assembled across systems. Erasure respects the retention you are legally required to keep — academic records that a board or university mandates are not silently deleted.

Breach obligations

If a personal data breach affects your institution we notify you without undue delay, with what we know and what we are doing, so you can meet your own reporting duty to the Data Protection Board and to affected people.

This describes how the product is built. It is not legal advice, and your institution remains responsible for its own compliance.

AI and your records

Your data does not train anybody's model

The question every IT committee now asks, answered plainly.

No training on your data

Student records, documents and messages are never used to train or fine-tune a model, ours or a vendor's. Processing happens to answer your request and for nothing else.

Agents work inside permissions

An AI agent can reach exactly what the role it acts for can reach. It cannot read a record a human in that seat could not open, and every action it takes lands in the same audit trail.

Draft mode by default

Agents start proposing rather than sending. You review the first weeks of output, then decide, agent by agent, what is allowed to act on its own.

Evaluating us

What we hand over before you sign

Ask for any of it. None of it is gated behind a sales stage.

Security documentation

Architecture, hosting regions, encryption, backup and retention schedules, and our current certification status in writing.

Data processing agreement

The DPA, the sub-processor list, and the retention and deletion terms that apply when the contract ends.

Your questionnaire

Send your own security questionnaire and we complete it. If an answer is no, it will say no rather than something that reads like yes.

Questions

What IT committees ask first

Do you hold ISO 27001 or SOC 2?

We give our current certification status in writing during evaluation, alongside the security documentation and sub-processor list. We do not display a badge for an audit we have not completed, because a badge is the one claim a procurement team will check.

Do you use our data to train AI models?

No. Your records are processed to answer the request in front of them and for nothing else. They are not used to train or fine-tune any model, ours or a third party's, and they are not pooled with other institutions' data.

Who at Ivake can see our records?

Support access to a live institution needs a stated reason, expires, and is written to the audit trail you can read yourself. It is not open-ended, and it is not available to everyone at the company.

What happens to our data if we leave?

You get a full export of every record and document in open formats, on request, at any point — including after the contract ends. Deletion then follows the schedule in the agreement. We do not hold data hostage to keep a customer, and we will not make you ask twice.

Can we host it ourselves, or in our own cloud account?

A dedicated database or a private deployment in an Indian region is available for groups and universities whose policy requires it. Fully on-premise is a different conversation and depends on what your IT team can commit to operating.

Do you carry out penetration testing?

Ask us for the current testing position and scope during evaluation and we will tell you what has been done and when. If your institution wants to run its own test against a staging environment, we will arrange it.

Book a demo

See Ivake running on your own data

Send us a sample before the call: a term of enquiries, a fee structure, or a class list. We load it and set up your programmes, so you see your own institution on screen rather than a demo account.

  • 45 minutes, your data. Not a generic tour of features.
  • Migration mapped on the call. We show exactly where your current records land.
  • A written rollout plan within two working days, with phases, owners and dates.
  • No pressure to switch everything at once. Most schools and colleges start with one department or one intake.