#01Purpose and status
ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) publishes this statement to explain its information security commitments for the Academyship education and institution management platform and the public resources available to Institutions.
This is a public statement. It is not the confidential, management-approved Information Security Policy used within Academyship's internal information security management system. It does not add to or reduce the commitments in an applicable Order Form, the Terms of Service or the Data Processing Addendum (DPA).
#02Information and services covered
Academyship handles information through its platform, Institution workspaces, portals, APIs, generated documents and supporting services. Depending on the modules an Institution uses, that information can include student and guardian records, employee and payroll information, financial records, messages, assessment records, signing evidence, health and wellbeing details and regulated identifiers.
Modules are available by plan and configuration. The Privacy Policy describes the information handled through each module. Academyship's internal certification scope will be defined through its ISMS programme; this public description is not a certified scope statement.
#03Security objectives and commitments
Academyship's security approach is directed at protecting confidentiality, integrity and availability: limiting access to authorised people, protecting information against unauthorised change or loss, and supporting recovery when a service is disrupted.
The DPA, particularly Annex II Part A, sets out the technical and organisational measures Academyship commits to implement and maintain for production Customer Data. These include tenant separation, encryption, access controls, logging, secure development, vulnerability management, backups, incident response, supplier governance and personnel confidentiality and training. This statement explains those commitments; it does not assert an independent audit result.
#04Access and shared responsibility
Academyship is responsible for the security of its platform and managed infrastructure and for the conduct of its own personnel. Institutions are responsible for authorising their Users, assigning appropriate roles, managing credentials, configuring available controls, removing access that is no longer needed and governing the integrations they choose.
Annex II Part A of the DPA requires multi-factor authentication for privileged and administrative access. Academyship's personnel access to Customer Data is restricted by role, limited to an authorised purpose and the minimum necessary scope and duration, and logged as described in the DPA and Privacy Policy. The availability and configuration of controls for other User roles should be confirmed for the relevant Institution and module. An Institution's settings do not remove Academyship's own obligations.
#05Hosting and other processing locations
Academyship's published Terms, DPA and Privacy Policy state that its core production platform and Customer Data are hosted on AWS in Sydney, Australia (ap-southeast-2). This includes the platform backup arrangements described in those documents.
Australian hosting does not mean that every service or every recipient operates only in Australia. Disclosed telecommunications delivery, Stripe payment services, Customer-selected Integrations, calendar services chosen by Users and authorised access can involve handling outside Australia. The Privacy Policy and Subprocessor Register explain the relevant distinctions.
#06People and suppliers
The DPA requires personnel confidentiality, appropriate security-awareness training, restricted support access and supplier due diligence and contracting. Academyship's ISMS programme includes further documentation and evidence for workforce security, remote working, supplier assessment and access governance.
The Subprocessor Register identifies the providers Academyship appoints to process Customer Data. A Customer-selected Integration is different from an Academyship-appointed Subprocessor. Supplier assurance material relates to the supplier and must not be described as Academyship's own certification.
#07Development and vulnerability management
Annex II Part A of the DPA includes secure development, code review and testing, controlled changes, dependency and vulnerability scanning, and risk-based security patching. A published policy or a vulnerability scan does not by itself establish that an independent penetration test has been completed.
Security researchers should use the existing Report a Security Issue policy. That policy defines the narrow permitted research scope and the circumstances requiring prior written authorisation. This statement does not extend that scope or authorise testing of customer accounts, payment functions, signing workflows or live records.
#08Incidents and continuity
The DPA sets out Academyship's incident-response and customer-notification commitments. Security Incidents and Data Breach Response explains reporting routes, response stages and the distinction between contractual notice and statutory notification.
Business Continuity and Recovery explains the published backup and recovery commitments and Institution responsibilities. This statement does not promise an uptime percentage, recovery deadline or zero data loss. Any separately agreed service target is governed by the agreement that sets it out.
#09ISO 27001 and assurance status
Academyship does not currently hold ISO/IEC 27001 or SOC 2 certification. ISO/IEC 27001:2022 is on Academyship's security roadmap. Preparing policies or undertaking readiness work does not establish certification, and no certification date is guaranteed by this statement.
If Academyship obtains certification, its public assurance information will identify the certificate's scope and issuing certification body. AWS compliance material concerns AWS infrastructure and is not an Academyship certificate. Security-related public statements also do not establish ATO production access or approval of payroll calculations.
#10Information available to Institutions
Institutions can review the DPA, Privacy Policy, Subprocessor Register, Data Retention information, security reporting policy and other documents in the Legal Centre. Security questionnaires and further information can be requested through team@academyship.com.au. The audit and information rights in DPA section 19 continue to apply.
Information is provided subject to appropriate confidentiality and security restrictions. Academyship does not publish credentials, detailed infrastructure configuration, customer records, unresolved vulnerabilities or confidential audit working papers.
#11Contacts
Report suspected security incidents and vulnerabilities to security@academyship.com.au. For a vulnerability, follow Report a Security Issue. Privacy requests and concerns go to privacy@academyship.com.au; service faults go to support@academyship.com.au; child-safety concerns go to safety@academyship.com.au. In an immediate emergency in Australia, call 000.
#12Review and related documents
Academyship reviews this public statement when a material security, service, hosting, supplier or assurance change requires an update. The version and dates at the top identify the current published statement. Questions about the document can be sent to legal@academyship.com.au.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 11 October 2026 | Initial publication of the public information security statement; distinguished contractual commitments, internal ISMS work and certification status. |