Security & data protection
Security you can verify, not simply take on trust
Student Radar handles attendance, behaviour, SEND and safeguarding records: some of the most sensitive data a school holds. The controls behind that work should stand up to practical scrutiny.
Every material claim below links to the document behind it. Hosting, certification, AI, retention and contractual boundaries are stated at the level the published evidence supports.
Controls you can inspect
Hosting, encryption, access and retention claims sit beside the published source document that supports them.
Boundaries made explicit
The page separates primary hosting from other processing, base certification from higher levels, and review templates from signed agreements.
People stay accountable
Your school remains the controller, optional AI stays school-controlled, and professional judgement remains the decision point.
Published control evidence
Six controls, each linked to its evidence
Security language is useful only when a buyer can trace it back to a current document. These are the control statements procurement teams most often need first.
Cyber Essentials is the base certification. The page does not claim Cyber Essentials Plus or ISO 27001.
UK-hosted primary database
The primary pupil database is configured in Supabase’s eu-west-2 London project. Application hosting and optional or user-triggered services have separate processing boundaries documented below.
Source document: Sub-Processor ListEncrypted at rest and in transit
The primary data platform uses AES-256 encryption at rest, and current published controls require TLS 1.2 or higher for data in transit.
Source document: Information Security and Controls SummaryStrict access control
Multi-factor authentication is mandatory for every staff account. Role-based permissions and database-level controls mean each person sees only the pupils and records their role requires.
Source document: Information Security and Controls SummaryCyber Essentials certified
Certified under the UK government-backed Cyber Essentials scheme, which covers the core technical controls that stop the most common attacks. This is the base certification, not Cyber Essentials Plus or ISO 27001.
Source document: Cyber EssentialsYou control retention
Your school sets how long records are kept. After a subscription ends we delete live data within 30 days and encrypted backups age out within 90, unless you instruct otherwise or a legal hold applies.
Source document: Data Retention and Deletion ScheduleYou remain the data controller
Your school or trust stays the data controller. SENDlink Ltd, trading as Student Radar, acts as your processor. The DPA published here is the review copy for your legal team; the version you sign arrives with your Order Form.
Source document: Data Processing Agreement - Review Template
AI features inside the platform are optional and switched on by your school. Before any text reaches an AI model, our own Inkwell engine finds personal details and replaces them with tokens, and it does that in the browser: the identifying text never leaves the device. Deterministic UK identifier rules always run, and an on-device model adds context for the awkward cases. Staff see what has been replaced and confirm it before anything is sent.
We do not treat that as a reason to stop checking. Automated detection is never the last word on a safeguarding record, so recommendations stay advisory and a member of staff decides. Student Radar makes no automated pupil decisions under Article 22 of the UK GDPR, and nothing your school sends is used to train AI models.
Our free public tools, Echo and the Sensory Profiler, run separately and only when a visitor asks them to. They never receive a pupil’s name, school, year group or SEND status: the Sensory Profiler sends only the generic pattern selections the visitor ticked, and rejects free text outright. Nothing sent to them is used to train AI models, and our AI provider deletes its own abuse-monitoring copy within 30 days. Our Privacy Policy sets out exactly what each tool sends and how long anything is held.
Processing and recovery
Know where the boundaries sit and what happens next
Primary database location is only one part of the picture. Buyers also need the supplier boundary, optional services, backup window and incident response position in plain language.
Sub-processors
Four suppliers are core to running the platform: Supabase (UK-hosted database, sign-in and storage), Vercel (application hosting), Wonde (your MIS integration) and Upstash (London-based traffic limiting, which never sees pupil data). Twilio, Resend, Sentry and the in-platform AI features are optional and switched on by your school. The complete current list, with what each one does and where it processes data, is in our downloadable Sub-Processor List.
Retention and resilience
Encrypted backups are kept for up to 90 days so we can restore your data if something goes wrong. We have a documented incident response process, so if a security event ever affects your school you hear it from us quickly and in plain terms, with what happened and what we are doing about it.
Documentation for procurement
Give your reviewers the evidence, not another promise
Your procurement team can download everything they normally ask for, including our Sub-Processor List, AI Transfer Overview, Business Continuity Summary, Incident Response Policy and Cyber Essentials certificate. If something they need is not there, ask us and we will tell you where it stands.
