Trust centre
Everything a university needs to assess this platform before putting it in front of students. Where a document is in draft or does not exist yet, this page says so rather than leaving you to find out.
Where your data lives
- Application hosting
- Vercel, London (lhr1) region
- Database and authentication
- Supabase, EU/UK region
- Data residency commitment
- United Kingdom and European Economic Area
- Encryption in transit
- TLS 1.2 or above, HSTS enforced
- Encryption at rest
- AES-256, managed by the database provider
No student personal data is transferred outside the United Kingdom or the European Economic Area for storage. Where a subprocessor’s own operations touch data in the United States — request logs, for example — the transfer relies on Standard Contractual Clauses and the UK Addendum, and is listed individually on the subprocessor page.
Before we approach a university
Absent, these end the conversation in the first meeting.
Privacy notice
AvailableWhat personal data the platform holds, why, for how long, and the rights a student has over it. Written against what the application actually does.
- Reviewed by
- Data protection officer, students
Terms of use
AvailableThe terms a student agrees to. Separate from the institutional contract, which governs the university.
- Reviewed by
- Legal, students
Accessibility statement
AvailableConformance against WCAG 2.2 AA, stated honestly: what has been tested, what has not, and the known exceptions. Universities have Equality Act 2010 obligations, so this is checked, not skimmed.
- Reviewed by
- Accessibility and digital inclusion team
Subprocessor list
AvailableEvery third party that processes personal data on our behalf, what they do, where they hold it, and the transfer safeguard where one applies.
- Reviewed by
- Data protection officer, IT
Information security overview
AvailableAuthentication, authorisation, tenant isolation, encryption, logging, backups and dependency management, described at the level an IT reviewer can assess.
- Reviewed by
- IT security
Data flow and hosting
AvailableWhere data is stored and processed, which regions, and how it moves between the application, the database and each subprocessor.
- Reviewed by
- Data protection officer, IT
To negotiate the first contract
Asked for during procurement and legal review, not before.
Data processing agreement
In draftThe Article 28 terms under which we process student data on the university's instructions: scope, purposes, retention, deletion, subprocessors, security and breach notification.
- Reviewed by
- Legal, data protection officer
- Outstanding
- Solicitor review before it is offered to a customer.
Data retention schedule
AvailableHow long each category of data is kept, what triggers deletion, and what happens to student records when a contract ends.
- Reviewed by
- Data protection officer
Incident response procedure
AvailableHow a suspected breach is detected, contained, assessed and reported — including the 72-hour notification path to the university as controller.
- Reviewed by
- IT security, data protection officer
Business continuity and disaster recovery
In draftRecovery objectives, backup regime, and what a student sees during an outage. Honest about what is achievable at our current size.
- Reviewed by
- IT, procurement
- Outstanding
- A restore has to be rehearsed and the result recorded before this is credible.
Cyber Essentials certification
Not yet startedThe UK government-backed baseline. Frequently a hard requirement in public-sector procurement and cheap to obtain relative to what it unlocks.
- Reviewed by
- Procurement, IT security
- Outstanding
- Self-assessment and certification. The single highest-leverage credential at this stage.
Insurance certificates
Not yet startedProfessional indemnity and cyber liability cover, at the levels a university contract requires.
- Reviewed by
- Procurement
- Outstanding
- Cover to be arranged. Contract templates commonly specify a minimum; check before quoting.
Support and service levels
In draftResponse targets, support hours, escalation route and the availability commitment.
- Reviewed by
- Procurement, IT
- Outstanding
- Commit only to targets that can be met by the people who actually exist.
As we scale
Expected by larger buyers and by any public-sector framework.
Penetration test summary
Not yet startedAn independent test of the platform, with the remediation record.
- Reviewed by
- IT security
- Outstanding
- Not yet commissioned. Expect to be asked for this by any university buying for a whole cohort; budget for it before the second contract.
ISO/IEC 27001
Not yet startedA full information security management system, independently audited.
- Reviewed by
- Procurement, IT security
- Outstanding
- Deliberately not a Phase 1 goal. Meaningful only with the headcount to operate the management system it certifies.
Ask us directly
If a security questionnaire, DPIA or accessibility audit needs something not listed here, ask. A specific question gets a specific answer, including where the answer is “not yet”.
Contact us