Security Overview

Security at SchoolWeb

SchoolWeb applies layered technical and operational safeguards to protect school, staff, student, and parent information. This page summarises our current security controls.

Last updated: 14 March 2026

Encryption

TLS in transit and encrypted storage at rest

Australian Hosting

Primary infrastructure in Australian regions

Access Control

Role-based permissions and authenticated sessions

Monitoring

Ongoing logging, review, and security updates

1. Scope and Governance

This page describes the security controls used by SchoolWeb, operated by Sky Network Pty Ltd. These controls apply to production services, account management, school data processing, and related support processes. Our approach to security is layered — combining technical controls, operational practices, and ongoing review to reduce risk across our platform.

2. Data Residency

  • Primary production infrastructure is hosted in Australian regions
  • Payment processing is handled by Stripe under their own security and compliance programme
  • School data is not used to train AI models
  • Where third-party service providers process limited data outside Australia, we select providers with strong privacy and security commitments and minimise the data shared

3. Data Protection Controls

SchoolWeb applies the following technical data protection measures:

  • All connections to the platform use HTTPS with TLS encryption in transit
  • Production data is stored using encrypted storage at rest
  • Passwords are stored as salted cryptographic hashes — plaintext passwords are never stored or logged
  • Input validation and server-side authorisation checks are applied to protected actions and API endpoints
  • Automated backups support data recovery in the event of failure

4. Identity and Access Management

SchoolWeb includes eight built-in roles — Super Admin, Admin, Teacher, Staff, Editor, Student, Parent, and Viewer — each with defined permission boundaries. These controls enforce the principle of least privilege across the platform.

  • Authenticated sessions are required to access protected features and API endpoints
  • Administrative actions are restricted to authorised users with appropriate roles
  • Privileged activity is logged and reviewable by school administrators
  • Session protections are applied to reduce exposure from credential compromise

5. Platform Security Operations

  • Security-relevant events and logs are monitored on an ongoing basis
  • Identified vulnerabilities are triaged and remediated according to risk severity
  • Backup and recovery processes are maintained and reviewed regularly
  • Security updates and dependency patches are applied as part of ongoing platform maintenance
  • Multi-factor authentication (MFA) is available for administrator and staff accounts to provide an additional layer of access security
  • Software dependencies are monitored for known vulnerabilities and updated as part of the regular maintenance cycle

6. AI Security

SchoolWeb includes optional AI-assisted features for content creation, page generation, and an in-platform assistant. When AI features are in use:

  • Student personally identifiable information is excluded from AI provider requests
  • No student records are stored or retained on external AI platforms
  • AI processing is configured so school data is not used for provider model training
  • AI outputs are assistive only — staff are responsible for reviewing and approving AI-generated content before publication or use
  • Schools can disable AI features entirely through their platform settings

When schools self-host SchoolWeb and configure their own AI providers, the school is responsible for ensuring their chosen AI infrastructure meets applicable security and data processing requirements. SchoolWeb's software applies the safeguards listed above regardless of which AI provider is configured.

7. Incident Response and Notification

SchoolWeb maintains documented incident response procedures covering identification, containment, remediation, and post-incident review. Our notification obligations are aligned with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988.

  • Where school data is materially affected by a security incident, we target initial notice to affected schools within 72 hours of confirmed impact
  • Where an eligible data breach is identified, we notify the Office of the Australian Information Commissioner (OAIC) as required under the NDB scheme
  • Notifications include known scope of impact, affected data categories, containment status, and recommended next steps
  • We cooperate with affected schools so they can meet their own breach notification obligations to students, parents, and staff
  • Status updates are provided as material facts become available during an active incident

8. School Compliance Support

  • Schools may request a Data Processing Addendum (DPA) to support procurement and compliance requirements
  • Policy summaries and data handling information are available on request
  • Schools remain responsible for obtaining local policy approvals, parent and student consent, and meeting applicable education department requirements

9. Security Contact

Security concerns, suspected vulnerabilities, or data breach reports can be directed to [email protected]. We will acknowledge receipt within 48 hours and work to confirm and address reported vulnerabilities promptly. We welcome responsible disclosure from security researchers and school IT staff.

This page is a summary of current security controls and may be updated over time as the platform evolves. Detailed evidence of specific controls may be shared through controlled assurance channels for procurement and due diligence purposes.