Security
Last updated: 2 October 2026
MegaExams is a small, independent product. We would rather tell you exactly what we do than wave a badge at you. Here it is.
Certifications
We do not hold SOC 2 or ISO 27001 certification, and we have not had a third-party security audit. Everything below describes controls we run ourselves. If your district needs a questionnaire filled in, email us and we will answer it point by point.
Hosting
MegaExams runs on one DigitalOcean server in Bangalore, India (BLR1). The application, database, cache and uploaded files all live on that server. US hosting is available for schools that require it.
Network and server
- HTTPS only, with TLS 1.2 or 1.3. Plain HTTP is redirected to HTTPS, and browsers are told to use HTTPS only (HSTS).
- The database and cache listen only on the server itself and cannot be reached from the internet.
- Server login (SSH) accepts keys only, never passwords.
- A firewall allows only web traffic and SSH.
- Public pages and sign-in are rate limited to slow down abuse and guessing.
Accounts and access
- Students sign in with a one-time code sent to their email. Codes expire after 10 minutes and allow only a few tries. A student can optionally set a password.
- Teachers sign in with an email code or a password. Passwords are stored only as bcrypt hashes.
- Every school's data is separated by account. Owners and admins manage the whole school; teachers manage only their own content.
- Webcam proctoring photos and student answer and doubt photos are served only to signed-in teachers of the owning school (and a student can see their own answer photos). Anyone else, including anyone with a copied link, gets a "not found" page.
- Session cookies are HttpOnly and SameSite, and forms are protected against cross-site request forgery.
- Google Classroom tokens, when a teacher connects Classroom, are encrypted before they are stored.
- We do not offer two-factor authentication or single sign-on (SAML or Google sign-in) today.
- School owners and admins can view a log of data exports, deletion requests, setting changes and each time a teacher opened one student's detailed result or proctoring evidence.
Privacy by design
- Usage analytics (Microsoft Clarity) runs with all text and inputs masked on every teacher and student page.
- IP geolocation uses a database on our own server; no IP address is sent to a third party for it.
- Webcam proctoring takes still photos only, with no audio, no face recognition and no emotion or attention scoring.
- Teacher deletions go to a 30-day Trash, then are permanently deleted.
- Schools can turn AI processing off so no student answer is sent to OpenAI.
- Webcam photos are deleted automatically after the school's retention period (new schools start at 90 days).
Backups
The database is backed up every night and each backup is kept for 7 days. Backups are stored on the same server; they are not encrypted separately and are not copied off-site today. This protects against mistakes and software faults, not against the loss of the whole server.
If there is a security incident
- We contain it first: shut off the affected access, rotate keys and passwords.
- We work out what happened, which schools and which data are affected.
- We notify each affected school within 72 hours of confirming a breach of its data, by email to the account owner, with what happened, what data was involved, what we have done, and who to contact.
- We help the school meet its own notice duties to parents and regulators, and send a written follow-up once the investigation is complete.
Report a security issue
If you find a vulnerability, please email prasanth@megaexams.com with the details. We will reply within 3 working days, keep you updated, and credit you if you wish. Please do not access other people's data, and give us a fair chance to fix the problem before you share it.