Security
Last updated: August 29, 2026
Edus is designed for institutions that depend on accurate academic data. Security is built into how we host, access, and operate the platform.
Transport and access
- HTTPS enforced for all public site traffic
- Role-based access so staff see only what their job requires
- Prepared statements and server-side validation on data endpoints
Application protections
- Rate limiting on public form endpoints
- Honeypot spam filtering on waitlist and contact forms
- Restricted access to configuration, vendor, and private directories
- Security headers including X-Content-Type-Options and X-Frame-Options
Data handling
We collect only data needed to operate the Site and waitlist. See our Privacy Policy for details. Production credentials are stored outside version control in server-side configuration files.
Reporting issues
If you discover a security vulnerability, email hello@edus.app with details. We investigate good-faith reports promptly.