OBCRM Enterprise safeguards sensitive student records, passports, financial ledgers, and sub-agent network agreements with multi-tenant database isolation, AES-256 encryption capability, and controls aligned to SOC 2 principles. Our SOC 2 audit is a self-assessed readiness program, not yet a completed third-party certification.
Logical database scoping enforces strict `companyId` context separation on every query, preventing cross-tenant data leakage.
Traffic is served over HTTPS/TLS. We maintain a per-tenant AES-256 envelope-encryption module with key rotation, being progressively rolled out across stored records, alongside automated off-site backups.
Role-Based Access Control provides granular branch permissions alongside immutable audit logging for all administrative actions.
Student lead applications, visa document vaults, and multi-branch accounting ledgers are backed up automatically off-site, with verification and restore tooling in place.
Encryption, tenant isolation, audit logging, and vulnerability management.
Read documentationHow and where student and organizational data is stored and protected.
Read documentationLive uptime status and incident history.
Read documentationWhat data we collect, why, and your rights over it.
Read documentationThe legal terms governing use of the platform.
Read documentationThe cookies we use — and the ones we deliberately don’t.
Read documentationContact our Security & Governance team for completed CAIQ questionnaires, architecture diagrams, or our SOC 2 readiness documentation under NDA.
Request Security Package