Platform Policy & Acceptable Use Guidelines
Read the Ellifo ERP Platform Policy covering acceptable use, account security responsibilities, and system availability commitments for institutions.
99.9% Cloud Uptime
Monthly measurement across production environment with 24h maintenance notice.
Zero Scraping / Spam
Strict acceptable use enforcement with automated perimeter telemetry and rate controls.
Role-Based RBAC
Confidentiality of credentials, admin delegation & instant access revocation.
AES-256 & TLS 1.3
Continuous perimeter protection and institutional infrastructure isolation.
1. Acceptable Use
In practice, this covers day-to-day activity such as recording attendance, managing admissions and fee collection, generating report cards and certificates, and communicating with staff, students, and parents through the platform's built-in messaging tools. It does not extend to activities like harvesting contact lists for purposes unrelated to your institution, sending unsolicited bulk communication outside normal school correspondence, attempting to bypass API rate limits or access controls, or uploading files intended to disrupt or compromise the platform. Institutions found in breach of this policy may have the relevant account access suspended while the matter is reviewed, and repeated or serious violations may result in termination of service.
Authorized Operational Use
Attendance, admissions, fees, gradebooks & verifiable certificates.
Zero Scraper Tolerance
Immediate rate-limiting & IP blocking against harvesting scripts.
Sanctioned Communications
Official parent/student alerts only; zero commercial solicitations.
Prohibited Behaviors & Perimeter Abuse
Automated heuristics monitor ingress traffic across all tenant VPC clusters. The following actions result in immediate session eviction and institutional notification:
Harvesting staff, student, or guardian directory records using headless browsers, curl routines, or unapproved third-party aggregators.
Disseminating unauthorized commercial marketing, third-party promotions, or bulk correspondence irrelevant to institutional operations.
Circumventing API burst thresholds, reverse-engineering endpoint tokens, or performing unauthorized vulnerability scanning.
Injecting weaponized binaries, macro-enabled spreadsheets, or corrupted payloads through document submission portals.
2. Account Security
Each institution designates its own administrators, who in turn provision accounts for teachers, accountants, and other staff with role-based access appropriate to their responsibilities. We recommend using unique, strong passwords for every account, enabling any available two-factor authentication, and promptly revoking access when staff members leave or change roles. Ellifo will never contact you by email, phone, or message to request your password — treat any such request as fraudulent and report it to our support team immediately.
Designated Admin Control
Granular role provisioning for teachers, accountants, and registrars.
Multi-Factor Authentication (MFA)
Mandatory 2FA recommended across all root campus tiers.
Immediate Deprovisioning
One-click access revocation upon faculty or staff departure.
Anti-Phishing Guarantee
Zero unsolicited password inquiries from Ellifo staff.
3. System Availability
Uptime is measured across our production environment on a monthly basis. Wherever practical, planned maintenance windows are scheduled outside typical school operating hours to minimize disruption, and status updates are posted as a banner on the administrative dashboard and, where relevant, sent to the registered institutional email address. Events outside our reasonable control — such as internet backbone outages, upstream hosting incidents, or force majeure events — are excluded from our uptime commitment, though we will keep affected institutions informed as we work to restore service.
99.9% Monthly Uptime Calculation
Continuous multi-zone failover architecture24-Hour Advance Dashboard Notice
Advance alert prior to infrastructure updatesOff-Peak Maintenance Windows
Scheduled specifically between 01:00 - 04:00 AM ISTLive System Status Dashboard
Transparent metrics monitored at status.ellifo.comEmergency Patching Protocol
Critical zero-day cybersecurity patches and perimeter updates that protect student records may be deployed without standard advance windows. In these exceptional cases, an emergency post-incident briefing is issued to institutional administrators within 2 hours of deployment.
Incident & Abuse Reporting
If your institution suspects credential compromise, abnormal API bursts, or unauthorized record exfiltration, follow our standardized escalation workflow:
Isolate & Revoke
Log into the Ellifo Security Console and immediately terminate all active sessions for the compromised user account.
Dispatch Alert
Email [email protected] with the subject line
[URGENT ABUSE INCIDENT] including affected tenant ID and
timestamp.
Forensic Audit
Our team provides audit trails, IP geographic provenance logs, and remediation guidance within the 2-hour SLA response window.
Frequently Asked Policy Questions
Clear institutional clarifications regarding acceptable usage constraints, uptime calculation models, and emergency protocols.
What constitutes unauthorized data scraping under Ellifo's policy? expand_more
What happens if a faculty member's password is compromised? expand_more
How does Ellifo notify institutions of emergency maintenance? expand_more
Can an institution request scheduled maintenance exceptions during exam weeks? expand_more
What is the procedure for reporting a security vulnerability or abuse? expand_more
Have questions regarding institutional compliance, API allowances, or campus security audits?
Our compliance architects and perimeter engineers collaborate directly with university IT directors to ensure frictionless, audited deployments.