Software Authenticity
Indelo installers are EV Authenticode-signed and distributed through CABS-controlled licensing and release channels.
Windows shows a verified publisher on signed installers. Public visitors cannot generate licences or freely access binaries; releases remain governed through administrator-controlled entitlement and institution portal access.
Offline-First Licensing
A signed enterprise license package is the primary authorization model. Online activation enhances connected deployments but is not a startup dependency.
Core institutional operation remains available when connectivity is weak or unavailable. Activation, heartbeat, update eligibility, and support visibility are connected enhancements — not the foundation of trust.
Data Ownership
Indelo is engineered around customer-controlled data movement and institution-owned operational records.
The synchronization model avoids a readable third-party relay as a requirement. File-first packages, local networks, VPNs, and approved institution channels remain central.
Synchronization Trust
Teacher spokes, campus hubs, and HQ consolidation use chained, signed, version-aware packages with scoped authority and auditability.
Synchronization packages detect and refuse silent modification, replay, gaps, out-of-order imports, and version drift. Sync cannot bypass the same business-rule validation used by local entry.
Academic Records Integrity
Academic records are long-duration institutional trust assets, not ordinary editable data.
Locks, approvals, audit trails, signed records, and verification workflows preserve the credibility of results and report records across staff changes, disputes, and campus expansion.
Security & Responsible Disclosure
Security issues should be reported responsibly so CABS can protect institutions, releases, portals, and public infrastructure.
The Trust Center links security, support, disclosure, documentation, and portal-only implementation guidance in one place.
Honest Boundary
Tamper-evidence proves records were not altered after entry; it does not prove the original entry matched reality.
That remaining risk is procedural. Indelo controls it through approvals, role accountability, audit review, reversals, reconciliation, and institutional verification workflows.