Security designed around responsibility.
COUNSIVA is designed so access follows operational responsibility, not convenience. The goal is to reduce unnecessary exposure while keeping authorized teams productive.
Tenant separation
Customer environments are separated by tenant context and application-level authorization controls. A user should only operate inside the tenant and scope assigned to them.
Role, branch and country scope
Access can be constrained by role and operational scope, including branch and country permissions. This supports organizations where counsellors, managers, finance staff and administrators require different levels of visibility.
Platform administration boundary
Platform administration is treated separately from tenant CRM authority. Platform administrators manage platform and governance functions but do not receive tenant-confidential CRM access by default.
Private files and documents
Student photos and documents are stored in private cloud storage and are intended to be accessed through authorized application flows rather than public object URLs.
Authentication and session controls
Administrative and portal access use authenticated service paths and security controls appropriate to the role. Session and access events can be recorded to support investigation and accountability.
Auditability
Important administrative and security events are designed to leave auditable records so changes and access decisions can be reviewed when needed.
Backups and recovery
Production database operations include backup and point-in-time recovery capabilities. Recovery procedures are treated as controlled operational actions and are not performed casually against live data.
Secrets and runtime configuration
Sensitive runtime values are intended to be provided through managed secret mechanisms rather than committed into source code or exposed to client-side applications.
Shared responsibility
Security also depends on customer actions. Customers should assign only necessary access, remove access promptly when roles change, protect credentials, review permissions regularly and avoid sharing confidential records outside authorized channels.
Responsible reporting
If you believe you have identified a security issue, do not attempt to access or modify data beyond what is necessary to demonstrate the issue. Use the official contact channel published by COUNSIVA so the report can be handled safely.
This page describes the platform's security approach and should not be interpreted as a certification or guarantee that has not been independently issued.