Independently Tested & Verified

Security and privacy built in from day one.

SOLASTIAN is built for international schools that handle sensitive staff and student data. Every layer of the platform, from infrastructure to authentication, is designed with security and GDPR compliance in mind.

Hosted securely in Europe.

SOLASTIAN runs on Microsoft Azure in the West Europe region (Netherlands). Your school's data never leaves the European Economic Area.

Microsoft Azure, West Europe

All application and database servers are hosted in Azure's Netherlands data centre, within the EEA and subject to EU data protection law.

Automated backups

Per-school database backups run automatically and are stored in Azure Blob Storage. Retention policy: 7 daily, 4 weekly, and 3 monthly snapshots per school.

High availability

The platform is monitored continuously. Incident status and uptime history are published publicly at solastian.com/status/.

Every school is completely isolated.

Complete data isolation is enforced at the database level, guaranteeing the highest level of privacy and security for every school.

Access you control

SOLASTIAN staff cannot access your users' records. If you ever need help, access can only be granted by your school administrator, and only for the duration of the support session.

Private subdomain per school

Every school accesses SOLASTIAN through its own subdomain (e.g. myschool.solastian.com). Sessions and authentication are scoped to that subdomain.

Strong authentication on every account.

Multi-Factor Authentication (MFA)

Use your phone to verify your identity. Works with Google Authenticator, Authy, and any standard authenticator app. Admins are required to enable MFA, enforced automatically after a 24-hour grace period.

Hardware security keys

Admins can authenticate with physical security keys (such as YubiKey) for the strongest available protection. No phone required.

Backup codes

Static backup codes are generated at MFA setup, allowing account recovery if a device is lost. Codes are hashed and stored securely.

Automatic session protection

Accounts lock automatically after 30 minutes of inactivity. Only one active session is allowed per account. Signing in on a new device signs out the previous one.

GDPR compliant by design.

Encryption

  • All data in transit encrypted via TLS 1.2+
  • Sensitive credentials encrypted at rest using industry-standard AES encryption
  • Passwords are never stored, only a secure one-way fingerprint
  • Database connections encrypted

GDPR

  • Data hosted exclusively within the EEA
  • No data sold or shared with third parties
  • Cookie consent with granular controls on all public pages
  • Data Processing Agreement (DPA) available on request
  • Right to erasure supported. Contact us to delete your school's data

Regularly penetration tested

We run automated penetration tests before every release to ensure SOLASTIAN meets the security standards your school deserves.

Found a security issue?

We take all security reports seriously. Contact us directly and we'll respond within 48 hours. Reach us at security@solastian.com.