Back to Insights & Articles
Architecture & Security

Multi-Tenant Cloud Architecture: Why Separate Databases Ensure 100% Data Isolation for Schools

AU
AURA Security Team
Chief Information Security Officer
25 Sep 2026• 6 min read

In standard legacy SaaS software, hundreds of schools are crammed into a single shared database table distinguished only by a fragile "school_id" column. A single coding oversight or SQL injection flaw can accidentally expose one school's student contact records, teacher payroll, or examination questions to another.

AURA was architected with a strict **Separate Database Per Institution** paradigm: - **Central Discovery Registry**: The central database stores only high-level directory discovery metadata (School Name, Public Code, Custom Theme, and Domain). - **Dedicated Tenant Database Containers**: Every enrolled school or college operates on its own dedicated PostgreSQL container with isolated credentials and encryption keys. - **Cryptographic Verification**: Student transcripts, certificates, and financial receipts are signed cryptographically, allowing anyone to verify their authenticity while keeping private records secure. - **Complete Data Ownership**: If an institution ever decides to export its data or host an internal archive, 100% of its database can be exported in standard SQL formats with zero cross-tenant contamination.

This architecture ensures maximum compliance, high-availability uptime, and peace of mind for institutional boards and governing bodies.

See this system in action on your campus

We provide full database onboarding, staff training, and bKash setup within 7 days.

Schedule an Onboarding Call