Architecture and security

Everything on this page is checkable.

Where something is not in place, this page names it and gives the date it is due. We would rather lose a tender on this page than in an implementation.

Last reviewed [DATE] · Owner [NAME, ROLE]

The short version

Phishing-resistant sign-in for every role, included. Passkeys and SSO against Entra ID and Google Workspace, at no extra cost.

Wellbeing, medical, counselling and child-safety records are separately governed. A classroom teacher never sees a counselling note through a general wellbeing permission.

Audit records reads as well as writes, and you can query it yourself. Most school privacy incidents are someone opening a record they should not have. Our own support access appears in the same log you read.

Australian hosting, onshore support, no offshore access to your tenant. Support access is time-boxed, consented to by you, and audited.

Your data out, in documented formats, on request, at any time. It is available at any point in the relationship, and we do not charge for it.

What is not in place yet is listed at the bottom of this page. Read that first if you are short of time.

Everything above is expanded, with the specifics, in the nine sections below.

Completing a security questionnaire?

01

Identity

Phishing-resistant sign-in is included for all roles at no extra cost. Schools are targeted, staff reuse passwords, and charging extra for the control that prevents the incident is the practice this product exists to argue with.

PasskeysWebAuthn, platform and roaming authenticators. Available to all roles including students, at no additional cost.
Single sign-onSAML 2.0 and OpenID Connect against Microsoft Entra ID and Google Workspace. Group-to-role mapping, so leavers lose access the moment your directory records their departure.
Multi-factorTOTP and WebAuthn. Enforceable per role, so you can require it of staff with wellbeing access without imposing it on Year 4 students.
SessionsPer-device sessions, revocable individually by an administrator. Configurable idle and absolute lifetimes, set separately for staff and student roles.
Local accountsSupported for the roles that cannot be in your directory: casual relief staff, external coaches and parents, with the same MFA options.
02

Authorisation is per record class.

Most systems grant "wellbeing" as one permission. That collapses a counselling note, a behaviour entry and a reportable-conduct record into a single switch, and it is why staff end up seeing things they should not. Kestrel separates them, and the data layer enforces the separation.

Record classDefault reachNotes
Pastoral entries Teachers of the student, tutor, head of house Positive and negative observations, awards, detentions.
Wellbeing Head of house, wellbeing staff Visible as an alert to classroom teachers without exposing the entry text.
Medical Nurse, front office; alerts to staff who supervise Conditions and action plans surface on rolls and excursion lists. Treatment detail stays out of them.
Counselling Named counsellors only Health information. Excluded from general wellbeing reads and from exports by default.
Child safety Named officers only Separate store, separate audit stream, retention floor of 45 years, legal hold available.
Family and financial Registrar, business office Parenting orders and per-guardian permissions govern what each parent receives.

Kestrel enforces a court order. Where a parenting order restricts contact, collection or correspondence, the restriction is a property of the relationship record. Reports, messages and portal access route accordingly.

If your permission model is more complicated than this, with boarding houses, multiple campuses or a counsellor shared with another school, describe it and we will show you how it maps, or tell you that it does not.

Bring it to a walkthrough
03

Audit you can query yourself.

What is recordedReads as well as writes on all sensitive record classes. Actor, subject, action, timestamp, source address and session. Reads matter: most school privacy incidents are someone opening a record they should not have.
Who can read itYour administrators, directly, without raising a support ticket. Filterable by person, by student, by record class, by date.
IntegrityAppend-only. Kestrel staff cannot alter your audit history, and our own access to your tenant is written into the same stream you can read.
Retention[RETENTION PERIOD — CONFIRM], exportable for your own archive.
04

Hosting and residency

RegionMelbourne, Victoria. Student data is stored and processed in Australia, on a virtual machine in that region.
SupportOnshore. No offshore access to your tenant, and support access is time-boxed, consented to by you, and audited.
TenancyLogically separated per school, with tenant identity enforced at the query layer.
EncryptionTLS 1.2+ in transit, AES-256 at rest, including backups.
Subprocessors[PUBLISHED LIST AND CHANGE-NOTICE PERIOD — CONFIRM]. The list should be public and you should be told before it changes.
05

Resilience

Recovery point[RPO — CONFIRM]
Recovery time[RTO — CONFIRM]
Restore testingA restore is only real once it has been performed. [TEST CADENCE AND LAST TEST DATE — CONFIRM]
StatusA public status page with incident history. Past incidents stay published.
Your data, on exitA complete export in documented formats, on request, at any point in the relationship, and at no charge.
06

Assessments and obligations

Independent verification, and the regulation that binds us directly.

Safer Technologies 4 Schools (ST4S)
The national schools privacy and security assessment. Effectively the ticket to sell into the sector.
Status: confirm
Independent penetration test
Annual, by an external firm, with the summary letter available under NDA.
Status: confirm
Children's Online Privacy Code
Binds us directly as well as you. The draft explicitly covers school management systems.
Due 10 Dec 2026
Australian Privacy Principles
Data minimisation, purpose limitation, and a breach-notification commitment with a stated maximum time to notify you.
Status: confirm
Retention and disposal
Per-record-type schedules aligned to state archives requirements, with the 45-year floor for child-safety-relevant records and legal hold overrides.
Status: confirm
07

The API is public, and so are its docs.

No partner programme, no gate, no sales call to see the reference. If you cannot get your own data out without asking us, it is not your data.

DocumentationPublic and versioned. Readable before you are a customer: the reference is here.
AuthenticationOAuth 2.0 with scoped tokens. Scopes follow the same record classes as the permission model, so an integration cannot reach counselling notes because it was granted attendance.
BrokersKestrel is a Wonde source, and exports OneRoster and School Data Sync. One integration on your side makes Kestrel a source for the downstream catalogue you already use.
Bulk and BIDocumented bulk export suitable for Power BI and school warehouses. It is a supported path.
WebhooksRecord-change events to subscribed systems. [AVAILABILITY — CONFIRM]
08

Reporting a vulnerability

If you have found something, we want to hear about it before your students do. Report to [SECURITY@ — CONFIRM]. We will acknowledge within one business day, keep you updated while we fix it, and credit you publicly unless you would rather we did not. We will not threaten you.

09

What is not in place yet.

Each vendor's security page lists what they have. This is the other half. If a control below matters to your tender, ask us about it directly and we will tell you where it stands.

[ITEM — e.g. ISO 27001 certification][TARGET]
[ITEM — e.g. customer-managed encryption keys][TARGET]
[ITEM — e.g. school-facing sandbox environments][TARGET]
[ITEM — e.g. SIEM log forwarding to your own tooling][TARGET]

We would rather you found this page uncomfortable than found the same information after signing.

Completing a security questionnaire?

Tender matrices want a document. The security pack contains our completed questionnaire responses, the ST4S assessment, the most recent penetration test summary under NDA, our subprocessor list, and the data-processing terms.

Request it at [SECURITY@ — CONFIRM]. We will send it whether or not you are in a live procurement with us, and we will not ask you to sign anything to read the parts that are already public.

Bring your IT manager.

Forty minutes. They will have harder questions than this page answers, and they should ask them.

Book a walkthrough