Skip to main content
Security & privacy for education

Security & Compliance built for education — from day one.

Academyship helps protect student and staff data with encryption, access controls, audit trails, backups, monitoring, and privacy-first workflows—designed for schools, RTOs, colleges, and multi-campus institutions.

01.
Encryption Everywhere
Encryption Everywhere
Encryption Everywhere
Encryption Everywhere

Data protected in transit + at rest.

02.
Access Controls
Access Controls
Access Controls
Access Controls

Role-based permissions & visibility.

03.
Audit Trails
Audit Trails
Audit Trails
Audit Trails

Know who changed what & why.

04.
Resilience
Resilience
Resilience
Resilience

Backups & disaster recovery.

Security Overview v1.0 Last reviewed: 18 July 2026 Owner: Academyship Security & Privacy Team

Security Posture at a Glance

A concise, evidence-based summary of what is available today, what is planned, and what is available by arrangement. It is the front door to our security and procurement resources.

Data Residency & Subprocessors

Australian-region hosting is available on Enterprise deployments. The default hosting region, backup handling, and logging arrangements are confirmed with your institution during onboarding.

We use a small number of infrastructure and email subprocessors to run the platform. A current subprocessor list (name, purpose, location) is available on request as part of the security pack.

Request the subprocessor list

Compliance Status

We align our practices to the Australian Privacy Principles (APPs) and maintain a data-breach response process consistent with the Notifiable Data Breaches (NDB) scheme.

Academyship does not currently hold ISO 27001 or SOC 2 certification, and we do not claim any certification, penetration test, or audit report until it has been independently completed. These are on our compliance roadmap.

Vulnerability Reporting

Found a security issue? Please report it to our team so we can investigate. We will acknowledge your report and work with you toward a resolution. Please avoid publicly disclosing details until a fix is in place.

team@academyship.com.au

  • Available

    Encryption in Transit & at Rest

    Modern TLS in transit; strong encryption at rest with managed keys.

  • Available

    Role-Based Access Control

    Scoped permissions by role, campus, and department, with approval gates.

  • Available

    Multi-Factor Authentication (MFA)

    MFA for staff sign-in. Enforcement policy is set per institution.

  • Available

    Audit Trails & Activity Logs

    Key actions logged with user, timestamp, and context for review.

  • Available

    Automated Backups & Recovery

    Automated backups with versioned, deletion-protected recovery.

  • Planned

    SAML / OIDC Single Sign-On

    Directory and IdP integration planned for enterprise plans.

  • By arrangement

    Australian-Region Hosting

    Available on Enterprise deployments; confirmed during onboarding.

  • Planned

    Independent Penetration Test

    Scheduled before enterprise general availability; not yet completed.

Enterprise Security Layer · Identity + Governance

Identity, Access & Governance Engineered with Enterprise Controls

Behind every Academyship environment sits a structured identity and governance framework designed to reduce risk, control permissions, and ensure accountability across teams, campuses, and departments.

Identity & Access Controls

Granular permissions that scale across institutes, campuses, and roles.

  • Role-based identity management
  • Policy-driven access rules
  • Multi-factor authentication (MFA) for staff sign-in

Organisational Governance

Clear boundaries that keep responsibilities and access clean.

  • Multi-organisation structuring
  • Account boundary controls
  • Policy enforcement layers

Secrets & Credentials Protection

Sensitive values stay sealed, encrypted, and controlled.

  • Encrypted secret storage
  • Credential rotation support
  • Secure parameter storage

Encryption Key & Certificate Management

Lifecycle controls for keys, certs, and encrypted channels.

  • Managed encryption key lifecycle
  • Hardware-backed key protection (enterprise roadmap)
  • Certificate lifecycle management

Access Monitoring & Change Tracking

Visibility into access, changes, and configuration drift.

  • Centralised access logs
  • Permission change detection
  • Configuration history tracking

Secure Identity Federation

Single sign-on and directory integration, planned for enterprise plans.

  • SAML / OIDC single sign-on (planned)
  • Directory service integration (planned)
  • Identity provider compatibility (planned)

Network Protection & Traffic Control

Controls that help keep traffic clean, segmented, and tightly governed.

  • Virtual private network segmentation
  • Network firewall filtering
  • Web application firewall protections

Threat Detection & Continuous Monitoring

Signals, logs, and detections that help surface what matters fast.

  • Behaviour-based threat detection
  • Security event aggregation
  • Automated configuration audits

Backup, Recovery & Continuity

Designed for continuity so operations can recover with confidence.

  • Automated backup policies
  • Versioned backups with deletion protection
  • Versioned storage recovery

Built on Layered Protection.
Not Guesswork.

Security in education requires more than a login screen. Academyship uses multiple layers—identity, data protection, network controls, monitoring, and governance—so risk is reduced across the entire platform.

Every
Layer
Matters.

Identity Icon

Identity & Access

  • Role-based access controls (RBAC)
  • Multi-factor authentication (MFA) for staff sign-in
  • Session controls + secure sign-in patterns
  • Admin approval flows for sensitive actions
Data Protection
24/7 ENCRYPTED

Data
Protection

  • Encryption at rest & in transit
  • Secure secrets handling
  • Data lifecycle controls (retention, deletion support)
Firewall

Network &
Perimeter

  • Segmented environments
  • Firewalls and traffic filtering
  • DDoS resilience patterns
CCTV Camera

Monitoring
& Detection

  • Centralised logs
  • Health checks + anomaly alerts
  • Operational visibility across services

Every sensitive action is monitored, logged, and reviewable across services.

Secure Engineering

Secure
Engineering

  • Change management
  • Code review practices
  • Security testing approach (XSS, injection, CSRF, etc.)
Resilience & Recovery

Resilience &
Recovery

  • Automated backups
  • Restore testing practices
  • Disaster recovery planning
SECURITY IN REAL WORKFLOWS

Security That Matches
Real Education Workflows.

Click a scenario to see the risk and how Academyship reduces it—using practical controls that map to how your teams actually work.

Protected

Mode

Risk

Protection

    Australian-region hosting is available on Enterprise deployments. Hosting location, backups, and logging are confirmed with you during onboarding.

    Privacy & Data Handling

    Privacy by Default so Your Team Stays Confident.

    Academyship keeps daily work simple while protecting sensitive education data in the background, with clear access boundaries, safe exports, and consent-aware communication.

    Built for Real Teams, Real Risks.

    Not everyone needs the same level of access. Academyship supports logical tenant isolation and organisation-isolated data boundaries so schools, RTOs, and multi-campus teams can work confidently without crossing lines they should not.

    Role-based access Audit-friendly exports Consent-aware comms

    We will email a short, procurement-friendly summary. No spam.

    Tip: We keep public security language practical and clear, focused on controls teams can verify during procurement and implementation.

    Privacy checklist

    Built-in patterns that reduce risk

    Always-on

    Data MinimisationWorkflows

    Only the fields you need

    Field-level capture limits
    Scoped forms by campus and team
    Retention-aware defaults
    DM

    Role-ScopedPortals

    Views tailored by role

    Student, parent, staff separation
    Portal modules by permission
    Access reviewed on role change
    RP

    Secure Exportsand Controls

    Permission-gated reporting

    Export approvals for sensitive data
    Download logs in audit trail
    Masked columns in external reports
    EX

    Consent-AwareCommunication

    Outreach that respects consent

    Consent checks before each send
    Parent and student preference sync
    Suppression safeguards for campaigns
    CC

    OwnershipBoundaries

    Organisation-isolated data

    Data partitioned by organisation
    Least-privilege access mapping
    Visibility scoped to assigned role
    OB
    Compliance posture Built for regulated education environments

    Compliance-Ready, with Australia in Mind.

    Academyship supports institutional compliance by enabling strong access controls, auditability, retention-friendly workflows, and security practices that align with common expectations in education and regulated environments.

    We Provide (Platform Controls)

    Security controls built into the platform, designed to reduce risk and support auditability.

    A

    Access control tooling

    Role-based permissions, scoped visibility, and approval gates for sensitive actions.

    L

    Audit trails

    Change history and activity logs to help you trace actions and support reviews.

    E

    Encryption mechanisms

    Protection for data in transit and at rest, with managed key practices.

    M

    Logging and monitoring

    Operational visibility, alerting, and observability for platform health and security signals.

    R

    Backup and recovery processes

    Recovery planning and restore-friendly practices to support continuity and resilience.

    Shield illustration representing shared compliance ownership

    You Control (Institution Policy)

    Governance choices your institution sets. These shape day-to-day risk and compliance outcomes.

    U

    User provisioning and role assignment

    Who gets access, which roles they hold, and how permissions are reviewed.

    R

    Internal retention policy

    Your institution defines how long records are retained and when they should be archived.

    T

    Staff training and governance

    Clear procedures, training, and periodic reviews keep policy aligned with practice.

    P

    Local procedures and approvals

    Approvals, escalation paths, and accountability for sensitive actions.

    Clear responsibility boundaries

    This split is intentional. It reduces legal ambiguity and helps procurement teams map controls to real-world governance.

    Trust Center - Security and Compliance

    Quick Answers for Procurement and IT.

    Clear, checklist-friendly answers to common security questions built for schools, RTOs, colleges, and multi-campus institutions.

    FAQs

    Click a question to expand. One open at a time.

    Smooth expand - accessible

    Academyship uses layered protection across identity, data, and operations. That includes encryption for data in transit and at rest, role-based permissions, scoped visibility by campus and department, audit trails for sensitive actions, and continuous monitoring to detect unusual activity.

    Yes. Academyship is designed to support auditability. Key actions can be logged with user identity, timestamps, and context so administrators can review activity, investigate incidents, and meet internal governance requirements.

    Data is protected in transit using modern TLS standards, and protected at rest using strong encryption. Sensitive values like secrets and tokens are stored using encrypted stores, and encryption keys follow managed lifecycle controls.

    Yes. Access can be managed through role-based permissions and organisation scoping. This helps ensure staff members only see what they need for their responsibilities, including support for multi-campus setups and department-level separation.

    Academyship supports resilience with automated backups, versioned recovery options, and restore processes. Recovery procedures are designed to minimise downtime and protect data integrity with continuity planning for critical services.

    Australian-region hosting is available on Enterprise deployments. As part of onboarding we confirm the hosting location, backup handling, and logging arrangements in writing so your governance and privacy obligations are clearly documented. Default hosting region is confirmed per deployment.

    We follow a security maintenance workflow that includes regular updates, dependency and vulnerability scanning, configuration monitoring, and incident response practices. Critical fixes are prioritised based on risk and potential exposure.

    Absolutely. If your institution has a vendor security questionnaire or checklist, we can provide a structured response and supporting materials based on your requirements.

    Tip: Press Tab to navigate and Enter to open.

    See security posture & resources

    Want a Security Walkthrough Tailored to Your Institution?

    Bring your checklist. We will map Academyship controls to your requirements and show how security works across student, academic, finance, HR, and reporting workflows with real screens, real permissions, and real audit trails.

    Talk to us about enterprise onboarding

    Typical response: within 1 business day

    Vendor checklist mapping Controls and risks overview Live product walkthrough

    Security Posture Highlights

    Snapshot

    Least-Privilege Access

    Roles, scopes, approvals, and session controls aligned to education workflows.

    Audit Trails and Change History

    Trace who did what, when, across sensitive actions and exports.

    What Your Team Gets

    A clear view of controls, responsibilities, and evidence you can take to procurement.

    Control Mapping

    We map your checklist items to platform controls and workflows.

    Evidence-Ready Answers

    Auditability, access boundaries, retention support, and recovery posture explained plainly.

    Shared Responsibility, Made Simple

    We provide platform controls. Your institution controls users, roles, and policies.

    We Provide

    Encryption, monitoring, auditability, backups, secure boundaries.

    You Control

    Provisioning, role assignment, retention policy, and internal approvals.

    Australian-region hosting is available on Enterprise deployments, confirmed with you during onboarding.