Security Policy
Security controls and responsibilities for EduInsight.
- Published
- 4 May 2026
- Last updated
- 5 January 2026
- Next review
- 5 January 2026
- Version
- Version 1
Security approach
EduInsight is built around role-based access controls, encrypted connections using HTTPS, provider-managed encryption at rest, auditable support access and secure operational processes.
The platform separates platform administration, organisation administration, school administration and staff access so users only see data appropriate to their role and active context.
We do not publish exact infrastructure providers, deployment locations, internal routes or other implementation-level operational details in public documents.
Access controls
Customer administrators control user access through school and organisation roles. Staff access is separate from school and organisation administration.
Support access is intentionally initiated, time-limited where supported, reason-based and logged for audit review.
Customers are responsible for inviting the correct users, removing leavers promptly and using appropriate internal policies for observation and evidence handling.
Operational safeguards
EduInsight monitors important service events such as authentication failures, invite delivery failures, billing events and directory sync errors.
Secure development practices include code review, testing, migration control and environment-based configuration.
Security concerns should be reported promptly so they can be triaged and addressed.
Security note
These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.
This policy is reviewed regularly to ensure compliance.