SEND records hold diagnoses, family circumstances and safeguarding history. Here is exactly how we protect them — in specifics, not adjectives.
Before any text leaves the platform for AI drafting, a five-layer redaction filter strips names, dates of birth, postcodes, NHS numbers and addresses — and replaces them only after the draft returns. The model works on an anonymous child, always.
| Layer | What it catches | How |
|---|---|---|
| 1 · Structured fields | Names, DOBs, addresses from the record itself | Stripped at source, never serialised |
| 2 · Pattern scan | NHS numbers, postcodes, phone numbers in free text | Regex + validators |
| 3 · Known-name dictionary | Every surname and contact name on the platform | Global redaction index |
| 4 · AI-assisted detection | Indirect identifiers pattern rules miss | Dedicated detection pass |
| 5 · Gateway guardrail | Anything that slipped through | Independent check at the network edge |
Databases and file storage in London (eu-west-2). AES-256 at rest, TLS 1.3 in transit. Data does not leave the UK.
Every table enforces tenant isolation in the database itself — a school can only ever query its own children.
AI output is always a draft for a qualified person. Nothing is sent to a parent or authority without human sign-off.
Cyber Essentials certified. ICO registered (ZC117599). UK GDPR & DPA 2018.
Legal guidance cites the Children and Families Act 2014 and SEND Code of Practice by section. No fabricated case law.
Whole-database backups every two hours with automated verification and off-site copies.
Data-processing agreement, sub-processor list, retention schedule and a completed security questionnaire are available on request — most schools clear us through their DPO in one pass.