WhatsApp Live Desk Direct Helpline: +91 7709196316
OFFICIAL INSTITUTIONAL GUIDELINES · ACCEPTABLE USE & SYSTEM INTEGRITY
verified SHA-256 Validated Policy Baseline · Registry Cert #EL-2026-AUP

Platform Policy & Acceptable Use Guidelines

Read the Ellifo ERP Platform Policy covering acceptable use, account security responsibilities, and system availability commitments for institutions.

calendar_today
Effective Date January 1, 2026
verified_user
Version Standard 3.4 Enterprise Platform
domain
Target Coverage Admins, Faculty, Students & Guardians
outgoing_mail Email Security Desk ([email protected])
Active Enterprise SLA Enforcement
99.9%
cloud_sync

99.9% Cloud Uptime

Monthly measurement across production environment with 24h maintenance notice.

Zero Scraping
shield

Zero Scraping / Spam

Strict acceptable use enforcement with automated perimeter telemetry and rate controls.

Granular
badge

Role-Based RBAC

Confidentiality of credentials, admin delegation & instant access revocation.

AES-256
lock

AES-256 & TLS 1.3

Continuous perimeter protection and institutional infrastructure isolation.

SECTION 1.0 Enforced Platform-Wide

1. Acceptable Use

The Ellifo platform is to be used solely for institutional management and educational purposes. Any attempt to use the platform for unauthorized data scraping, spamming, or malicious activities is strictly prohibited.

In practice, this covers day-to-day activity such as recording attendance, managing admissions and fee collection, generating report cards and certificates, and communicating with staff, students, and parents through the platform's built-in messaging tools. It does not extend to activities like harvesting contact lists for purposes unrelated to your institution, sending unsolicited bulk communication outside normal school correspondence, attempting to bypass API rate limits or access controls, or uploading files intended to disrupt or compromise the platform. Institutions found in breach of this policy may have the relevant account access suspended while the matter is reviewed, and repeated or serious violations may result in termination of service.

verified

Authorized Operational Use

Attendance, admissions, fees, gradebooks & verifiable certificates.

block

Zero Scraper Tolerance

Immediate rate-limiting & IP blocking against harvesting scripts.

mark_email_read

Sanctioned Communications

Official parent/student alerts only; zero commercial solicitations.

SECURITY TELEMETRY CLAUSE Zero Tolerance Perimeter

Prohibited Behaviors & Perimeter Abuse

Automated heuristics monitor ingress traffic across all tenant VPC clusters. The following actions result in immediate session eviction and institutional notification:

cancel Unauthorized Data Scraping

Harvesting staff, student, or guardian directory records using headless browsers, curl routines, or unapproved third-party aggregators.

cancel Unsolicited Bulk Spam

Disseminating unauthorized commercial marketing, third-party promotions, or bulk correspondence irrelevant to institutional operations.

cancel API & Rate Limit Tampering

Circumventing API burst thresholds, reverse-engineering endpoint tokens, or performing unauthorized vulnerability scanning.

cancel Malicious File Uploads

Injecting weaponized binaries, macro-enabled spreadsheets, or corrupted payloads through document submission portals.

SECTION 2.0 Identity Stewardship

2. Account Security

Institutions are responsible for maintaining the confidentiality of their administrative and faculty credentials. Ellifo is not liable for unauthorized access resulting from shared or weak passwords.

Each institution designates its own administrators, who in turn provision accounts for teachers, accountants, and other staff with role-based access appropriate to their responsibilities. We recommend using unique, strong passwords for every account, enabling any available two-factor authentication, and promptly revoking access when staff members leave or change roles. Ellifo will never contact you by email, phone, or message to request your password — treat any such request as fraudulent and report it to our support team immediately.

admin_panel_settings

Designated Admin Control

Granular role provisioning for teachers, accountants, and registrars.

key

Multi-Factor Authentication (MFA)

Mandatory 2FA recommended across all root campus tiers.

person_remove

Immediate Deprovisioning

One-click access revocation upon faculty or staff departure.

phishing

Anti-Phishing Guarantee

Zero unsolicited password inquiries from Ellifo staff.

SECTION 3.0 SLA Commitment

3. System Availability

We aim for 99.9% uptime. Planned maintenance will be communicated at least 24 hours in advance via the administrative dashboard.

Uptime is measured across our production environment on a monthly basis. Wherever practical, planned maintenance windows are scheduled outside typical school operating hours to minimize disruption, and status updates are posted as a banner on the administrative dashboard and, where relevant, sent to the registered institutional email address. Events outside our reasonable control — such as internet backbone outages, upstream hosting incidents, or force majeure events — are excluded from our uptime commitment, though we will keep affected institutions informed as we work to restore service.

99.9%

99.9% Monthly Uptime Calculation

Continuous multi-zone failover architecture
24h

24-Hour Advance Dashboard Notice

Advance alert prior to infrastructure updates
bedtime

Off-Peak Maintenance Windows

Scheduled specifically between 01:00 - 04:00 AM IST
speed

Live System Status Dashboard

Transparent metrics monitored at status.ellifo.com
Maintenance Clause 3.2

Emergency Patching Protocol

Critical zero-day cybersecurity patches and perimeter updates that protect student records may be deployed without standard advance windows. In these exceptional cases, an emergency post-incident briefing is issued to institutional administrators within 2 hours of deployment.

SECTION 4.0 Security Protocol

Incident & Abuse Reporting

If your institution suspects credential compromise, abnormal API bursts, or unauthorized record exfiltration, follow our standardized escalation workflow:

Step 01

Isolate & Revoke

Log into the Ellifo Security Console and immediately terminate all active sessions for the compromised user account.

Step 02

Dispatch Alert

Email [email protected] with the subject line [URGENT ABUSE INCIDENT] including affected tenant ID and timestamp.

Step 03

Forensic Audit

Our team provides audit trails, IP geographic provenance logs, and remediation guidance within the 2-hour SLA response window.

INSTITUTIONAL FAQ Operational Clarifications

Frequently Asked Policy Questions

Clear institutional clarifications regarding acceptable usage constraints, uptime calculation models, and emergency protocols.

What constitutes unauthorized data scraping under Ellifo's policy? expand_more
Extracting or systematically downloading student contact directories, fee ledgers, or employee information using automated crawlers, bots, or external scraping scripts.
What happens if a faculty member's password is compromised? expand_more
Administrators can instantly revoke active sessions and enforce an immediate password reset from the administrative access control console.
How does Ellifo notify institutions of emergency maintenance? expand_more
Emergency hotfixes are communicated via emergency in-app broadcast banners and priority SMS/email dispatch to registered campus technical leads.
Can an institution request scheduled maintenance exceptions during exam weeks? expand_more
Yes. Institutions can flag blackout windows during examination tabulation and admission deadlines, during which non-critical maintenance is completely deferred.
What is the procedure for reporting a security vulnerability or abuse? expand_more
Contact our dedicated Security Desk at [email protected]. Our engineering response team investigates with a 2-hour priority turnaround.
Compliance Advisory

Have questions regarding institutional compliance, API allowances, or campus security audits?

Our compliance architects and perimeter engineers collaborate directly with university IT directors to ensure frictionless, audited deployments.