Your students' data, protected — by design.
A business school runs on trust. This page explains, in plain language, exactly how Aula Magna safeguards the personal data of your students, faculty and alumni — in transit, at rest, and every day in between.
Encryption everywhere
TLS 1.2+ in transit (HSTS, preloaded) and AES-256 at rest. Data is never stored or transmitted in the clear.
Least-privilege access
Role-based access enforced in middleware before any page loads — students see only their own records. Multi-factor authentication available for staff and admin accounts, plus single sign-on through your institution's identity provider.
Full audit trail
Every meaningful action on personal data is logged with who, what and when — reviewable and exportable for your compliance team.
Backups & resilience
Automated, encrypted backups with point-in-time recovery, a documented backup & disaster-recovery plan, and a scheduled restore-test drill. A backup we've never restored is not a backup.
GDPR-first
EU data residency, a signed Data Processing Agreement, data minimisation, right to erasure, and 72-hour breach notification.
Hardened by default
Content-Security-Policy, clickjacking + MIME-sniffing protections, rate limiting, and automated dependency, static-analysis and secret scanning on every change.
Security is a program, not a promise
"Never breached" is not a one-time state — it's a set of things we run on a schedule, forever. This is the cadence behind the platform.
Data governance & GDPR
- Your school is the Data Controller; Aula Magna acts strictly as your Data Processor under a signed DPA (GDPR Art. 28).
- EU data residency — your data is hosted in the region you require.
- Data minimisation — we collect only what the platform needs to function.
- Right to access, correction and erasure, handled within statutory timelines.
- Personal-data breach notification within 72 hours, with a documented response runbook.
- A named Data Protection Officer you can reach directly.
Wrap, don't rip out
Aula Magna is designed to sit alongside your existing systems, not replace them. Your student system-of-record stays where it is and under your control — which means adopting Aula Magna does not create a risky data migration or a second copy of everything.
Subprocessors
We use a small, vetted set of infrastructure providers, each of which encrypts data at rest and maintains their own recognised certifications:
- Vercel — application hosting & edge network (EU region)SOC 2
- Neon — managed Postgres database (EU · Frankfurt)SOC 2 · ISO 27001
See the full subprocessor list and our Data Processing Agreement.
Certifications & roadmap
We believe in claiming only what is true. Today, the platform runs the encryption, access-control, monitoring and GDPR practices described above, with automated dependency, static-analysis and secret scanning on every change. An independent third-party penetration test is scheduled before our first institutional deployment, and we are working toward formal ISO 27001 (with SOC 2 Type II to follow) — happy to share our current status and roadmap, and our security document pack, under NDA.
Found a vulnerability?
We welcome responsible disclosure. Email security@aulamagna.io with details and we'll acknowledge within 2 business days. Please give us reasonable time to remediate before any public disclosure.
This overview describes the security posture of a production Aula Magna deployment. Specifics can be tailored to your institution's requirements — contact security@aulamagna.io. Last updated · 9 July 2026.