Security Overview
Our approach
This page summarises how we protect the EducatedOn platform and the data within it. We're happy to go into more detail - including completing security questionnaires - on request. Contact us at support@educatedon.com.
Encryption
-
In transit: all connections to the platform are encrypted using TLS 1.2.
-
At rest: customer data and backups are encrypted at rest using AES-256.
-
Integration credentials and access tokens for connected systems are stored encrypted and are never displayed back in full once saved.
Access control
-
Access to the EducatedOn platform is authenticated per user, with individual accounts - shared logins are not supported.
-
Passwords are stored hashed and salted, and are never stored in a recoverable form.
-
Role-based permissions allow customers to control what each of their users can see and do within their tenant.
-
Single sign-on (SSO/SAML) is not currently supported; it's on our product roadmap. Multi-factor authentication is available.
Internal access
-
Three 17 staff access to production systems is restricted to those who require it to perform their role, on a least-privilege basis.
-
Access is granted individually, reviewed periodically, and revoked promptly when someone changes role or leaves.
-
Staff access to customer data is limited to what is necessary to provide support and maintain the service, and this access is logged and reviewed regularly.
Tenant separation
Each customer operates within their own tenant, this consists of both a separate database per tenant and for specific services a shared database with logical, tenant-scoped separation. Configuration and credentials are segregated accordingly, so that one customer's users cannot access another customer's data.
Monitoring, logging and audit
-
Platform activity is logged, including authentication events and Process and Action executions.
-
Infrastructure monitoring for availability and for anomalous activity for continuous security assessment, threat detection and alerting, alongside Azure Web Application Firewall and Azure DDoS Protection at the network and application layers.
Backups and resilience
-
Customer data is backed up regularly, and backups are encrypted. A 35-day point-in-time database restore is available; for the filesystem, we take 30 days of rolling snapshots for disaster recovery purposes.
-
We target 99.5% uptime for the platform, measured monthly, as set out in our Service Levels.
-
Planned maintenance is communicated at least 24 hours in advance and scheduled to minimise disruption.
-
Backup restoration was last tested in July 2026, including a successful point-in-time restore, data integrity verification, and confirmation of application functionality on the restored data.
Secure development
-
Changes to the platform are reviewed before release.
-
We keep dependencies and underlying platform components patched and up to date.
-
Development and testing are carried out in environments separated from production, each with its own credentials, configuration and access controls.
-
We do not use live customer data in development or test environments; anonymised or synthetic data is used where realistic test data is required.
Vulnerability management and testing
We run static code analysis and dependency/CVE scanning throughout development, and third-party libraries are monitored for known vulnerabilities. We have not yet completed an independent penetration test; one has been commissioned as part of our ISO 27001 certification programme and is currently being scheduled.
Incident response
-
We maintain a process for identifying, investigating and responding to security incidents.
-
Where a personal data breach affects customer data, we will notify the affected customer without undue delay, in line with our obligations as a processor under UK GDPR, and provide the information the customer needs to meet their own notification obligations.
-
Suspected security issues can be reported to support@educatedon.com. We take all reports seriously and will acknowledge them promptly.
Sub-processors
We use a small number of sub-processors to deliver the service, including cloud hosting, software development and support providers, and business tooling. We require sub-processors to provide appropriate safeguards and to meet equivalent data protection standards. A current list is available on request, and our obligations are set out in our Data Processing Information.
Staff
-
Staff receive data protection and security awareness guidance appropriate to their role.
-
Contracts of employment and engagement include confidentiality obligations.
-
Right-to-work checks are carried out for everyone we engage.
Certifications
We do not currently hold ISO 27001 certification. We have an Information Security Management System in place, aligned with the principles of ISO/IEC 27001:2022, and are working towards formal certification with an accredited certification body; we anticipate completing this within the next 12 months. We hold Cyber Essentials Plus certification.
Your responsibilities
Security is shared. Customers are responsible for:
-
Managing their own users' access and removing access promptly when someone leaves
-
Keeping integration credentials for their connected systems secure and rotating them appropriately
-
Configuring Processes and Actions appropriately for the sensitivity of the data involved
-
Ensuring their own use of the platform complies with our Acceptable Use Policy
Questions
We're happy to discuss our security arrangements in detail, complete security questionnaires, or talk through specific requirements. Contact support@educatedon.com.