TRUST & SECURITY
Security at DiyoEdu
A thoughtful approach to protecting school information.
DiyoEdu is a school management product from G NOX Tech, offered as an online service and as an offline desktop edition for school computers. This page describes the security practices we can confirm for those editions today, and where we deliberately say less. Security is shared: it depends on the product, on how your school manages accounts, and on how school devices are maintained. For data handling, read our Privacy Policy; for contractual commitments, read our Terms.
Last updated
Draft preview. This page is not published or indexed until product and security owners approve every claim and the reporting contact.
On this page
Security in practice
Security questions usually land in one of three areas. Each card points to the section that answers it.
Access to school information
Every use of DiyoEdu starts with a person: a staff member opening the application or signing in to the online service. The first decision about access belongs to your school, which decides who should be able to use DiyoEdu and in what capacity. Schools where each person works under their own name, rather than through one shared login, can answer two simple questions later: who changed this record, and who should no longer have access.
We deliberately do not publish internal permission structures or account-recovery details on a public page. When you evaluate DiyoEdu with our team, ask what each kind of user can see and do in your edition, and keep your own written record of that for staff.
Access is also a habit, not only a setting. Review who has access once a term, remove it on the day staff leave, and keep passwords out of drawers and message groups.
Protecting information online
DiyoEdu Online runs in the browser. School records are held in the cloud service rather than on school computers, which makes the service itself the thing cloud-dependent schools rely on.
This page does not describe hosting configuration, encryption choices or backup schedules. If a detail like that matters to your decision, ask our team before you rely on it, and treat anything you do not find here as unconfirmed rather than as a guarantee in either direction.
Where a detail is left out, it is usually because publishing it would help an attacker more than a school. We would rather answer a direct question from your team than publish a partial picture.
Security for offline use
DiyoEdu Desktop is designed to run on your school's own computers. Day-to-day work continues when the internet drops. Records stay on those computers and move as encrypted files through your school's own Google Drive, as described on our Platform and Desktop pages.
Working offline changes who looks after the machine. Records that exist only on a school computer are under the school's care: who can sit down and open it, whether the operating system is kept current, whether it locks when unattended, and whether someone keeps school-controlled copies of important records.
Offline does not automatically mean private, encrypted, backed up or safe from loss. A stolen or failing computer takes its local data with it. Treat the desktop edition like any other part of your record-keeping: the same care as a filing cabinet, plus the routine care computers need.
Updates and maintenance
Software needs fixing after release, and DiyoEdu is no exception. Details differ between the online and desktop editions, so this page does not publish a patch schedule, a version number or an automatic-update promise. A schedule we could not keep would be worse than no schedule at all.
What we can say is simpler: problems are fixed and shipped to the edition they affect, and you can ask our team what applies to your installation at any time. On school computers, keeping the operating system and applications current is part of the same job, and that part stays with your school.
Supporting schools securely
Our published contact route is a phone call: the numbers on our Contact page are the ones we answer. When you contact us about an access problem, describe what you are seeing rather than sending credentials. A screenshot with student details removed tells us more than a password ever should.
If someone contacts you claiming to be from DiyoEdu and asks for a password or a student record, treat that as a warning sign and verify by calling the numbers we publish. Avoid sending passwords or student information through ordinary email or chat, including to us. There is almost always a safer way to share what is actually needed.
What schools can do
These habits do not replace the product's own protections; they sit alongside them. Six cover most of the ground.
- Prefer individual sign-ins over one shared login wherever your edition supports them, so responsibility stays clear.
- Review who has access once a term, and remove it on the day staff leave or change roles.
- Keep school computers updated and protected by a screen lock or password, especially those running the desktop edition.
- Keep school-controlled copies of records that live only on school machines, and check occasionally that you can open them.
- Share student information sparingly in email, chat and screenshots. Send the minimum needed and remove the rest.
- Report anything that looks wrong as soon as you notice it, using the channel below.
Report a security concern
If you find something that looks like a security problem in DiyoEdu, in the online service, the desktop application or this website, we would rather hear about it early than not at all.
Call +977 9814016996 or +977 9765321157 and say clearly that you are reporting a security concern. In the first call, describe what you saw and how we can reach you safely. Please do not include student data, passwords or live credentials. If we need to see something, we will arrange a safe way with you.
This is not a bug-bounty programme. It does not authorise testing against live school data, and it publishes no response deadline. What it does offer is a person to talk to. If an account problem is urgent, say so when you call.
Questions schools ask
Does the offline edition mean our data never leaves school computers?
No. The desktop edition is built to run locally, and its records move as encrypted files through your school's own Google Drive, as described on our Platform page. Records therefore exist in more than one place over time, and both places deserve care.
Who can see our school's information?
Your school decides who is given access in the first place, and should keep that decision under review. We do not publish our internal permission structure publicly; ask us to walk through what each kind of user can do in your edition. General data handling belongs in the Privacy Policy.
Who is responsible for backups?
Records that exist only on school computers are the school's to copy and keep, according to your own record-keeping rules. For the current practice on the online service, ask our team directly. This page does not describe backup arrangements, and an absent mention is not a promise either way.
How do we report a security concern?
Call the numbers published on our Contact page and say it is a security report. Do not include student data or passwords in the first message. The reporting section above has more detail.
How does this page relate to the Privacy Policy?
The Privacy Policy covers what personal information is collected and how it is handled. This page covers how the product and your school together keep school information safe. Where they overlap, the Privacy Policy is the fuller document.
