Security Overview: Platform & Data Safety
CrossLect security is the set of encryption, access, isolation, and monitoring controls that protect an academy's students, courses, and live video classes. It is built for coaching institutes, schools, independent tutors, and online academy owners who sell or run classes online and need to keep student data and paid content private.
CrossLect is developed, owned, and operated by DASHAH VENTURES (OPC) PRIVATE LIMITED in Hyderabad, India.
- Encryption256-bit SSL / TLS 1.3
- InfrastructureAWS + Cloudflare edge
- PaymentsPCI-DSS Level 1 gateways
- Data ownership100% academy owned
Who is CrossLect security built for?
CrossLect security is built for anyone running paid or private online classes: coaching institutes, schools, independent tutors, and academy owners. Use it when you need to protect student records, stop class-link sharing, and avoid handling card data yourself.
Coaching institutes
Protect paid batches, recorded lectures, and student lists.
Schools & colleges
Keep student records private and separate per institution.
Independent tutors
Stop class links from being shared outside your paying students.
Online academy owners
Run live classes and sell courses without handling card data.
How does CrossLect protect my academy's data?
CrossLect protects your academy with four controls: end-to-end encryption, full data ownership, watermarked live video, and automated threat blocking.
256-bit SSL/TLS encryption
Data in transit uses SSL/TLS 1.3. Data at rest uses AES-256.
100% data ownership
Your student list and course content belong strictly to you.
Dynamic video watermarks
Viewer-specific watermarks discourage screen recording in live classes.
Automated threat shield
DDoS defense and bot protection run on global edge networks.
What are the core security layers on CrossLect?
CrossLect uses four layers: data encryption, content protection, payment safety, and private tenant isolation. Each one covers a different risk, as shown below. Contact our team to learn more.
| Layer | What we do | Why it matters |
|---|---|---|
| Data encryption | SSL/TLS for all traffic; AES-256 for saved database files. | Stops outsiders from reading student or payment data. |
| Content protection | Dynamic viewer watermarks and token-locked access links. | Stops paid class links from being leaked or shared. |
| Payment safety | No stored credit cards. Payouts route through Stripe or Razorpay. | Removes payment compliance risk from your academy. |
| Tenant isolation | Each academy runs in an isolated environment on its own domain. | Keeps your students separate from other schools. |
Where is CrossLect hosted, and how is it kept online?
CrossLect is hosted on Amazon Web Services (AWS) and delivered through the Cloudflare edge network for uptime and speed.
Cloud hosting
Amazon Web Services (AWS) with automated real-time database backups.
Global delivery
Cloudflare Edge for fast loading and low video delay worldwide.
DDoS defense
Automated shields block brute-force logins and traffic spikes.
Which compliance standards does CrossLect follow?
CrossLect follows GDPR and Indian IT Rules for privacy, uses PCI-DSS Level 1 payment gateways, and aligns with SOC 2 Type II standards.
- Encryption
- 256-bit SSL / TLS 1.3
- Privacy rules
- GDPR & Indian IT Rules compliant
- Payments
- PCI-DSS Level 1 gateway integrations (Stripe, Razorpay)
- Audit readiness
- SOC 2 Type II standards
Who owns my student data on CrossLect?
You do. Your academy owns all student records and course content, and you keep three rights at all times:
We never sell data
We do not sell, rent, or trade your student list or contact numbers to advertisers or third parties.
Full export control
Download student records, attendance reports, and class logs at any time in standard formats.
Complete erasure
Delete a student or close your account and all associated records are purged from active storage.
Should I use CrossLect or generic meeting links for paid classes?
Use CrossLect for paid, recurring academy programs. Generic meeting links suit one-off informal sessions but lack per-student access control.
| Feature | Generic meeting links | CrossLect |
|---|---|---|
| Class link access | Anyone with the link can join | Token-locked links per student |
| Screen-recording deterrent | None | Dynamic viewer watermarks |
| Card data handling | Often stored in your own systems | Zero stored cards; Stripe or Razorpay |
| Student data separation | Shared folders and chats | Isolated tenant per academy |
| Best for | One-off informal sessions | Paid, recurring academy programs |
Frequently asked questions about CrossLect security
Yes. All traffic is encrypted with SSL/TLS, saved database files use AES-256, and each academy runs in an isolated environment.
No. CrossLect stores zero credit cards. Payments and payouts route directly through Stripe or Razorpay.
Your academy does. We never sell, rent, or trade your student list, and you can export it at any time.
Live classes use token-locked access links and dynamic viewer watermarks, so leaked links and screen recordings are discouraged.
On Amazon Web Services (AWS), delivered through the Cloudflare edge network, with automated real-time database backups.
All associated records are permanently purged from active storage when you delete a student or close your account.
Email security@crosslect.com with a clear description of the issue and steps to reproduce it.
How do I report a security vulnerability?
Email security@crosslect.com with the details. We take every report seriously and review it as quickly as possible. Follow these steps:
- 1Describe the issue and the page or feature affected.
- 2Add steps to reproduce it, plus screenshots if helpful.
- 3Email it to security@crosslect.com.
- 4Our security team reviews your report and replies by email.