Security & data protection

Organizations, HR & compliance teams can use QuizJhor with confidence — here's how we protect your data.

Tenant isolation

Database-level lockdown: row-level security is enabled on every table and all public/anon access is revoked — so nobody can read the database directly from outside our servers. Each organization's data is separated on the server, where every query is scoped to the organization identity carried by your session. This lockdown is re-applied and verified automatically after every database change.

Encryption & access

All traffic is encrypted over HTTPS/TLS. Login OTPs and session tokens are hashed; passwords are never stored in plain text. Role-based access (owner/admin/member/participant) — and our own privileged access requires a fresh OTP challenge plus a mandatory written reason, every time.

Hosting & data residency

The application and database are hosted in the Singapore region (Vercel + Supabase Postgres) with regular backups — so the answer to "where does our data live" is simply: Singapore. Payments are processed on bKash/SSLCommerz's own gateways — card/wallet credentials never touch our servers.

Data ownership & retention

Your data is yours. Results export to CSV, certificates are verifiable. On account closure, data is deleted on request. We never sell your data or use it for advertising.

Audit trail

Every sensitive action — payments, membership & role changes, admin settings, logins, account deletion — is written to an internal audit log, for compliance and investigations.

Need specific security answers or compliance documents? Read our standard DPA.

Contact us
← HomePricingPrivacy