Our Commitments
Security That Schools Can Rely On.
Three commitments that never change, regardless of plan, school size, or circumstance.
Encryption
Industry-Grade Encryption. Everywhere.
AES-256 at rest. TLS 1.2+ in transit. Every log, every export, every session. Not optional. Not configurable. Always on.
Student records are encrypted before they touch a disk and decrypted only on authorised request — with every access logged.
Data Sovereignty
All data stored in Australia.
No offshore servers. Not a preference — a commitment.
Student data never leaves Australian borders. Our infrastructure runs on Australian data centres, subject to Australian law, with no international data transfers — ever.
Access Control
Nobody Sees More Than They Need.
Teachers see their students. Coordinators see their school. Admins manage accounts — not records. Access is role-locked, not just permission-toggled.
When a teacher leaves, their access is revoked instantly. Their evidence logs remain — attached to the student, not the teacher.
Long-Term Archive
Once Logged — Tamper-Proof.
Every evidence log is archived for 7 years. Cryptographically signed on creation. Once logged, the record cannot be altered — only appended to.
This meets and exceeds Australian school records retention requirements. If you're ever audited, every entry has a timestamp, a logged-in user, and a cryptographic signature.
Our Promise
What We Will Never Do.
Privacy commitments should be specific, not vague. Here is exactly what we will never do — not as a policy footnote, but as a product-level guarantee.
Non-negotiable commitments
Sell student data to any third party, ever.
Use student records to train AI models.
Share evidence with any external service without explicit school consent.
Store data outside of Australian jurisdiction.
Retain data after account deletion beyond the required legal period.
Give staff access to data their role doesn't require.
Security Questions