info@aptsolutions.co.in  ·  +91 8849 335111 Serving universities since 2011 ISO 27001 & ISO 9001 aligned

Home/Security & Governance

Security, governance & audit

Custody, access, evidence

Examination data is not ordinary institutional data. It is time-critical, individually consequential and legally contestable. Our architecture is organised around three obligations: proving who held the answer book, constraining who could act on it, and retaining what is needed to answer a challenge later.

Identity segregation

Candidate identifiers are separated from the answer script by design, using a barcode sticker for examination metadata and an opaque holographic sticker to conceal the identity block. Evaluators operate against a UID that carries subject, section, medium, lot and serial — and nothing personal.

Access control

Roles are separated across supervisor, scanner, examiner and moderator functions, each with its own permissions and its own view. Evaluator access requires a registered credential plus a one-time password delivered to the registered mobile number.

Chain of custody

Each transfer is a recorded event: bundle receipt against the supervisor's report, manual count and discrepancy check, lot segregation, UID assignment, job card with page details, scan, allocation, evaluation, moderation, handover.

Data in transit and at rest

Scanned answer-book data is encrypted and transmitted to the central database, where it is stored subject-wise and UID-wise. Deployment can be arranged on institutional infrastructure where the institution requires data to remain within its own estate.

Retention and retrieval

Digital answer books are preserved for the institution's retention period and are retrievable by UID. The physical book remains intact because scanning is non-destructive, so the institution keeps both the record and the source.

Operational transparency

A live monitoring dashboard exposes expected, received, scanned, evaluated, moderated and rejected counts. Institutional stakeholders see the same numbers we do, during the cycle rather than after it.

Deployment

Controlled execution environments by preference

The evaluation client is deployed as a desktop application rather than a general web page. That is a deliberate choice: it narrows the execution surface, makes the endpoint an identifiable installed component, and keeps the marking interface out of a browser environment we do not control.

  • Desktop evaluation client. Downloaded from a supplied link by registered evaluators, activated against their credentials and one-time password.
  • Web dashboards for authorised stakeholders only. Monitoring views are provided to institutional coordinators and supervisors, not to the general evaluator population.
  • On-premise and hybrid options. Where an institution requires examination data to remain on its own infrastructure, deployment can be arranged accordingly during scoping.
  • Segregated environments. Demonstration and training environments are kept distinct from live examination data.

What we will not publish

This page describes controls at the level an examination committee needs to evaluate a vendor. It deliberately does not describe internal database structures, server addresses, credential handling internals or infrastructure topology.

Institutions conducting a formal technical evaluation, security review or tender assessment can request the detailed architecture and control documentation under a non-disclosure arrangement.

Standards

Framework alignment

Our processes are structured against recognised information security and quality management frameworks.

Information security

ISO/IEC 27001

Structured controls for protecting sensitive examination data, managing access and treating information security risk across scanning, barcoding, data processing and hosting activities.

Quality management

ISO 9001

Defined, repeatable and documented service delivery processes with continuous improvement — which in examination work translates directly into reconciliation discipline and cycle repeatability.

Process maturity

CMMI Level 5

Optimising-level practices governing how systems are designed, developed, deployed and maintained, with measurement and continuous improvement built into the delivery model.

Current certification documents and scope statements are provided to institutions on formal request as part of an evaluation, audit or tender process. See standards & certifications.

Due diligence

Questions worth asking any evaluation vendor

Including us. These are the questions that separate an examination specialist from a general IT supplier.

Is candidate identity removed physically, or only hidden in software?
Software-only masking means the identity is still present in the image and depends on the application behaving correctly. In our process the identity block is physically covered with an opaque sticker before the book is scanned, so it is not in the digital copy the evaluator receives at all.
Are answer books cut for scanning?
Ours are not. Book scanners image the answer book with the spine intact, preserving the original for audit, dispute or call-back.
What happens to marks between the examiner and the result?
In our system, nothing — and that is the point. Marks are recorded in the database at the moment of entry. There is no separate marks data-entry pass, and no manual totalling by the examiner, which removes the two most common sources of downstream discrepancy.
Can a re-evaluation request be served without re-handling the physical book?
Yes. The digital copy is retrieved by UID, awarded marks can be removed from the image, and a clean scanned copy is provided to the candidate.
Who holds the candidate mapping?
The institution. Compiled marks data is transferred to you for result processing; the resolution from UID to candidate happens in your systems.

Next step

Take the security model to your examination committee

We can present the control architecture, deployment options and audit evidence model directly to your COE office, IT department or evaluation committee.