Architecture and security
Everything on this page is checkable.
Where something is not in place, this page names it and gives the date it is due. We would rather lose a tender on this page than in an implementation.
The short version
Phishing-resistant sign-in for every role, included. Passkeys and SSO against Entra ID and Google Workspace, at no extra cost.
Wellbeing, medical, counselling and child-safety records are separately governed. A classroom teacher never sees a counselling note through a general wellbeing permission.
Audit records reads as well as writes, and you can query it yourself. Most school privacy incidents are someone opening a record they should not have. Our own support access appears in the same log you read.
Australian hosting, onshore support, no offshore access to your tenant. Support access is time-boxed, consented to by you, and audited.
Your data out, in documented formats, on request, at any time. It is available at any point in the relationship, and we do not charge for it.
What is not in place yet is listed at the bottom of this page. Read that first if you are short of time.
Everything above is expanded, with the specifics, in the nine sections below.
Identity
Phishing-resistant sign-in is included for all roles at no extra cost. Schools are targeted, staff reuse passwords, and charging extra for the control that prevents the incident is the practice this product exists to argue with.
Authorisation is per record class.
Most systems grant "wellbeing" as one permission. That collapses a counselling note, a behaviour entry and a reportable-conduct record into a single switch, and it is why staff end up seeing things they should not. Kestrel separates them, and the data layer enforces the separation.
| Record class | Default reach | Notes |
|---|---|---|
| Pastoral entries | Teachers of the student, tutor, head of house | Positive and negative observations, awards, detentions. |
| Wellbeing | Head of house, wellbeing staff | Visible as an alert to classroom teachers without exposing the entry text. |
| Medical | Nurse, front office; alerts to staff who supervise | Conditions and action plans surface on rolls and excursion lists. Treatment detail stays out of them. |
| Counselling | Named counsellors only | Health information. Excluded from general wellbeing reads and from exports by default. |
| Child safety | Named officers only | Separate store, separate audit stream, retention floor of 45 years, legal hold available. |
| Family and financial | Registrar, business office | Parenting orders and per-guardian permissions govern what each parent receives. |
Kestrel enforces a court order. Where a parenting order restricts contact, collection or correspondence, the restriction is a property of the relationship record. Reports, messages and portal access route accordingly.
If your permission model is more complicated than this, with boarding houses, multiple campuses or a counsellor shared with another school, describe it and we will show you how it maps, or tell you that it does not.
Bring it to a walkthroughAudit you can query yourself.
Hosting and residency
Resilience
Assessments and obligations
Independent verification, and the regulation that binds us directly.
The API is public, and so are its docs.
No partner programme, no gate, no sales call to see the reference. If you cannot get your own data out without asking us, it is not your data.
Reporting a vulnerability
If you have found something, we want to hear about it before your students do. Report to [SECURITY@ — CONFIRM]. We will acknowledge within one business day, keep you updated while we fix it, and credit you publicly unless you would rather we did not. We will not threaten you.
What is not in place yet.
Each vendor's security page lists what they have. This is the other half. If a control below matters to your tender, ask us about it directly and we will tell you where it stands.
We would rather you found this page uncomfortable than found the same information after signing.
Completing a security questionnaire?
Tender matrices want a document. The security pack contains our completed questionnaire responses, the ST4S assessment, the most recent penetration test summary under NDA, our subprocessor list, and the data-processing terms.
Request it at [SECURITY@ — CONFIRM]. We will send it whether or not you are in a live procurement with us, and we will not ask you to sign anything to read the parts that are already public.
Bring your IT manager.
Forty minutes. They will have harder questions than this page answers, and they should ask them.