Security

Secure by design. Auditable by default. Defensible when it matters most.

Security is not a single feature or technology. It is the outcome of well-designed processes, layered controls, operational discipline, and continuous accountability — built into every stage of the examination lifecycle.

Security begins long before exam day

Protecting an examination does not begin when the question paper is opened.

The Government of India's High-Level Committee on Examination Reforms recognised that strengthening examination integrity requires securing the entire examination lifecycle — from operational procedures and Standard Operating Procedures to technology, monitoring, and governance. We share the same philosophy. It begins with designing secure systems, disciplined processes, and clear accountability long before examination day.

Defence in depth

No single technology can secure an examination.

ExamProdigy applies multiple independent layers of protection so that examination integrity never depends on one device, one individual, or one security control. Every layer reinforces the next.

Layer 01

Process Security

Security starts with clearly defined workflows, controlled approvals, Standard Operating Procedures, and role-based responsibilities that minimise operational risk.

Layer 02

Physical Security

Controlled hardware, secure logistics, protected examination environments, and restricted physical access strengthen security beyond the digital layer.

Layer 03

Digital Security

Advanced encryption, time-based access controls, geo-fencing, offline operation, secure authentication, and hardened devices work together to protect examination content throughout its lifecycle.

Layer 04

Operational Security

Real-time monitoring, centralised administration, comprehensive audit logs, and controlled operational workflows provide complete visibility across the examination process.

Layer 05

Post-Examination Security

Automatic content removal, secure evidence preservation, complete audit trails, and documented chain of custody ensure examination integrity extends well beyond the examination itself.

Exact device, cryptographic, key-management, and retention specifications should be verified in technical documentation and during the pilot.
Security principles

Every security decision is guided by these.

Principle

Secure by Design

Security is built into every workflow from the outset, not added after implementation.

Principle

Defence in Depth

Multiple independent layers of protection ensure that no single point of failure compromises examination integrity.

Principle

Least Privilege

Every individual, device, and administrator receives only the access necessary to perform their authorised responsibilities.

Principle

Zero Trust

Every user, device, and request is verified before access is granted.

Principle

Audit by Default

Every critical event is recorded, creating complete transparency and accountability across the examination lifecycle.

Principle

Operational Resilience

Security measures are designed to support uninterrupted examination operations while maintaining the highest standards of integrity.

Technology that protects every stage

Controls that work together, not alone.

No single control secures an examination. Together, they create a secure, resilient, and auditable system.

Control

AES-256 Encryption

Control

Time-Locked Access

Control

Geo-Fenced Delivery

Control

Offline Examination Operation

Control

Role-Based Authentication

Control

USB Token Authorisation

Control

Hardened Examination Devices

Control

Comprehensive Audit Logs

Control

Automatic Content Removal

Security is also governance

Technology protects systems. Governance protects institutions.

ExamProdigy is designed to support clearly defined roles, controlled access, documented procedures, and complete accountability — enabling authorities to demonstrate fairness, transparency, and process integrity whenever required.

Roles

Clearly defined responsibilities

Every individual and device holds only the access their authorised role requires.

Records

Documented procedures

Standard Operating Procedures and controlled approvals, recorded rather than assumed.

Evidence

Complete accountability

Audit trails that let an authority demonstrate process integrity whenever it is questioned.

Secure by design. Auditable by default. Defensible when it matters most.

Test the model

Turn every security claim into an acceptance criterion.

Scope the threats, observe the controls, test failure paths, and retain the agreed evidence.