Trust & security

The most sensitive data a child has. Treated that way.

SEND records hold diagnoses, family circumstances and safeguarding history. Here is exactly how we protect them — in specifics, not adjectives.

The AI privacy pipeline

No child's identity ever reaches an AI model.

Before any text leaves the platform for AI drafting, a five-layer redaction filter strips names, dates of birth, postcodes, NHS numbers and addresses — and replaces them only after the draft returns. The model works on an anonymous child, always.

LayerWhat it catchesHow
1 · Structured fieldsNames, DOBs, addresses from the record itselfStripped at source, never serialised
2 · Pattern scanNHS numbers, postcodes, phone numbers in free textRegex + validators
3 · Known-name dictionaryEvery surname and contact name on the platformGlobal redaction index
4 · AI-assisted detectionIndirect identifiers pattern rules missDedicated detection pass
5 · Gateway guardrailAnything that slipped throughIndependent check at the network edge
Platform security

Boring, verifiable, in writing.

UK data residency

Databases and file storage in London (eu-west-2). AES-256 at rest, TLS 1.3 in transit. Data does not leave the UK.

Row-level security

Every table enforces tenant isolation in the database itself — a school can only ever query its own children.

Human-in-the-loop AI

AI output is always a draft for a qualified person. Nothing is sent to a parent or authority without human sign-off.

Certified

Cyber Essentials certified. ICO registered (ZC117599). UK GDPR & DPA 2018.

Cited, never invented

Legal guidance cites the Children and Families Act 2014 and SEND Code of Practice by section. No fabricated case law.

Backups, tested

Whole-database backups every two hours with automated verification and off-site copies.

For your DPO

Procurement-ready answers.

Data-processing agreement, sub-processor list, retention schedule and a completed security questionnaire are available on request — most schools clear us through their DPO in one pass.