TRUST

Security

How we protect school data: encryption, access control and backups.

  • Encrypted in transit and at rest
  • Role-based access

Schools hold some of the most sensitive data there is. Our security model assumes that, rather than treating it as an enterprise add-on.

Infrastructure

Hosted in UK regions with encryption in transit and at rest, isolated environments, and no production data in development or test systems.

Access control

Role-based permissions map to school roles, with least-privilege defaults. Staff access is logged and auditable, and Pippa inherits the requesting user's permissions exactly.

Resilience

Automated encrypted backups with regular restore testing, plus documented recovery objectives shared during implementation.

Testing and disclosure

Independent penetration testing on a recurring schedule, with remediation tracked to closure. Suspected vulnerabilities can be reported to us directly and we will acknowledge within one working day.