Security, described rather than promised

What protects your data today, how each control actually works, and what is still on the roadmap. Written for the person running the review, not for the brochure.

Why this page names its limits

Most security pages are written to reassure. This one is written to be checked, because that is what actually happens to it: an IT lead or a procurement officer opens it with a questionnaire beside them.

So each control below says what it does and how it is enforced, and the roadmap section says plainly what is not built yet. A gap you find here costs us a conversation. A gap you find during due diligence, after we implied otherwise, costs us the contract and costs you weeks.

If your review needs detail beyond this page, ask. We answer questionnaires directly rather than returning a brochure.

The controls that exist today

Each of these is implemented and can be demonstrated in a technical walkthrough.

Layered access control

Permission to open something is checked on several independent levels rather than once, so a single misconfiguration does not expose data. Access is granted per role and per action, not as one blanket setting.

Sensitive fields stay hidden

Identity documents, personal contact numbers and bank details can be withheld from roles that do not need them, even on records those roles are allowed to open. Seeing a student is not the same as seeing everything about them.

Institutions stay separate

One institution can never see the records of another, and within a group each campus keeps its own. Separation is applied consistently across the whole platform rather than screen by screen, and a record cannot be moved between institutions.

Reversible deletion

Records are retired rather than destroyed. A mistaken deletion during a busy admissions week is recoverable, and a deleted record keeps its history instead of vanishing from the audit.

Every change is attributable

Who created a record, who last changed it, who removed it and when. A disputed mark or fee has a history somebody can check months later, without needing a support ticket to reconstruct it.

Least-privilege staff access

Teachers see their assigned classes, sections and students rather than the whole institution. The default is the narrow view, widened deliberately, not the reverse.

What separation does and does not mean

This is the first thing a serious reviewer asks, so here is the direct answer. Your records are yours: another institution cannot see them, and within a multi-campus group each campus keeps its own data unless you deliberately share it. That separation is applied uniformly across the platform rather than implemented screen by screen, which is what makes it dependable instead of dependent on whoever built a given feature.

What it does not mean is physical separation. Institutions run on shared infrastructure with strict logical separation between them. If your policy requires dedicated infrastructure, or data held in a named country, we do not offer that today. That is on the roadmap below.

We would rather you knew that in the first conversation than at contract review. If your team needs to go deeper than this page, we will walk through it properly on a technical call under NDA.

On the roadmap, and not yet built

Stated so you can plan around it rather than discover it later. Ask us for current timelines during your review.

  1. Dedicated infrastructure per institution

    Not available today. Institutions with a hard requirement for physically separate infrastructure should treat this as a gap rather than a detail, and raise it with us early.

  2. Data residency guarantees

    We cannot currently commit to holding your data in a specific jurisdiction. If your regulator requires it, tell us early so we can be honest about fit rather than waste your evaluation.

  3. Independent security certification

    We hold no third-party security certification today. What we offer instead is direct access to the people who built the system and written commitments in your agreement.

  4. Full regional timezone support

    Date and time handling is being extended for institutions outside our core regions. Ask us where your region stands before you commit to a rollout date.

On this website

Separate from the product, and worth stating because you are reading it now.

Consent-gated tracking

No analytics or marketing tag loads until you allow it where consent is legally required, and every decision is recorded.

Encrypted in transit

This site and the product are served over HTTPS. Certificates are managed and renewed automatically.

Your enquiry data

A demo request is used to contact you about the demo. It is not sold, and you can ask us to delete it at any point.

Questions procurement teams ask

Is our data isolated from other institutions?
Yes, at the row level. Every record carries an organisation and a campus identifier, and those filters are applied in the data-access layer on every read and write rather than being left to individual queries. What that does not mean is a separate database per institution - isolation is enforced in software, in one shared database. If your policy requires physical separation, that is a gap today rather than a detail.
Can you guarantee our data stays in our country?
Not today. We cannot commit to holding data in a specific jurisdiction, so if your regulator requires it, tell us during the first conversation rather than at contract stage. We would rather be ruled out early than waste your evaluation.
Do you hold ISO 27001, SOC 2 or similar certification?
No. We hold no third-party security certification. What we offer instead is direct access to the engineers who built the system, a completed questionnaire rather than a brochure, and written commitments in your agreement.
How is access controlled internally?
Three independent gates: whether the module is visible to that role, whether the plan entitles the institution to it, and whether the individual has permission for that specific action. Passing one does not pass the others. Sensitive fields such as identity documents and bank details can also be masked from lower roles on records they can otherwise open.
What happens when a record is deleted?
It is retired rather than destroyed, so a mistaken deletion during a busy admissions week is recoverable and the record keeps its history instead of vanishing from the audit. Every row also stores who created it, who last changed it and when.
Who can see student personal data?
Teaching staff see their assigned classes, sections and students rather than the whole institution - the narrow view is the default, widened deliberately. Administrative access is granted per role and per action, and sensitive columns can be masked independently of whether the record itself is visible.
Can we complete our own security questionnaire with you?
Yes, and we complete it directly rather than returning marketing material. If your team would rather talk to the people who built the system than read a document, we arrange that instead.
What happens to our data if we leave?
You can export your records whenever you want them, in formats you can actually use, and that does not depend on how the relationship ends. Retention and deletion terms after termination are recorded in your agreement rather than left to us.

Running a security review?

Send us your questionnaire and we will complete it directly. If you would rather talk to the engineers who built this, we will arrange that instead.

Contact us