Back to policies

Security Policy

Security controls and responsibilities for EduInsight.

Published
4 May 2026
Last updated
5 January 2026
Next review
5 January 2026
Version
Version 1

Security approach

EduInsight is built around role-based access controls, encrypted connections using HTTPS, provider-managed encryption at rest, auditable support access and secure operational processes.

The platform separates platform administration, organisation administration, school administration and staff access so users only see data appropriate to their role and active context.

We do not publish exact infrastructure providers, deployment locations, internal routes or other implementation-level operational details in public documents.

Access controls

Customer administrators control user access through school and organisation roles. Staff access is separate from school and organisation administration.

Support access is intentionally initiated, time-limited where supported, reason-based and logged for audit review.

Customers are responsible for inviting the correct users, removing leavers promptly and using appropriate internal policies for observation and evidence handling.

Operational safeguards

EduInsight monitors important service events such as authentication failures, invite delivery failures, billing events and directory sync errors.

Secure development practices include code review, testing, migration control and environment-based configuration.

Security concerns should be reported promptly so they can be triaged and addressed.

Security note

These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.

This policy is reviewed regularly to ensure compliance.

Back to policies
Security Policy | EduInsight Observe | EduInsight Observe