Identity & Access Controls
Granular permissions that scale across institutes, campuses, and roles.
- Role-based identity management
- Policy-driven access rules
- Multi-factor authentication (MFA) for staff sign-in
Academyship helps protect student and staff data with encryption, access controls, audit trails, backups, monitoring, and privacy-first workflows—designed for schools, RTOs, colleges, and multi-campus institutions.
Data protected in transit + at rest.
Role-based permissions & visibility.
Know who changed what & why.
Backups & disaster recovery.
A concise, evidence-based summary of what is available today, what is planned, and what is available by arrangement. It is the front door to our security and procurement resources.
Australian-region hosting is available on Enterprise deployments. The default hosting region, backup handling, and logging arrangements are confirmed with your institution during onboarding.
We use a small number of infrastructure and email subprocessors to run the platform. A current subprocessor list (name, purpose, location) is available on request as part of the security pack.
We align our practices to the Australian Privacy Principles (APPs) and maintain a data-breach response process consistent with the Notifiable Data Breaches (NDB) scheme.
Academyship does not currently hold ISO 27001 or SOC 2 certification, and we do not claim any certification, penetration test, or audit report until it has been independently completed. These are on our compliance roadmap.
Found a security issue? Please report it to our team so we can investigate. We will acknowledge your report and work with you toward a resolution. Please avoid publicly disclosing details until a fix is in place.
Encryption in Transit & at Rest
Modern TLS in transit; strong encryption at rest with managed keys.
Role-Based Access Control
Scoped permissions by role, campus, and department, with approval gates.
Multi-Factor Authentication (MFA)
MFA for staff sign-in. Enforcement policy is set per institution.
Audit Trails & Activity Logs
Key actions logged with user, timestamp, and context for review.
Automated Backups & Recovery
Automated backups with versioned, deletion-protected recovery.
SAML / OIDC Single Sign-On
Directory and IdP integration planned for enterprise plans.
Australian-Region Hosting
Available on Enterprise deployments; confirmed during onboarding.
Independent Penetration Test
Scheduled before enterprise general availability; not yet completed.
Behind every Academyship environment sits a structured identity and governance framework designed to reduce risk, control permissions, and ensure accountability across teams, campuses, and departments.
Security in education requires more than a login screen. Academyship uses multiple layers—identity, data protection, network controls, monitoring, and governance—so risk is reduced across the entire platform.
Every sensitive action is monitored, logged, and reviewable across services.
Click a scenario to see the risk and how Academyship reduces it—using practical controls that map to how your teams actually work.
Risk
Protection
Australian-region hosting is available on Enterprise deployments. Hosting location, backups, and logging are confirmed with you during onboarding.
Privacy & Data Handling
Academyship keeps daily work simple while protecting sensitive education data in the background, with clear access boundaries, safe exports, and consent-aware communication.
Not everyone needs the same level of access. Academyship supports logical tenant isolation and organisation-isolated data boundaries so schools, RTOs, and multi-campus teams can work confidently without crossing lines they should not.
We will email a short, procurement-friendly summary. No spam.
Tip: We keep public security language practical and clear, focused on controls teams can verify during procurement and implementation.
Privacy checklist
Built-in patterns that reduce risk
Academyship supports institutional compliance by enabling strong access controls, auditability, retention-friendly workflows, and security practices that align with common expectations in education and regulated environments.
Security controls built into the platform, designed to reduce risk and support auditability.
Access control tooling
Role-based permissions, scoped visibility, and approval gates for sensitive actions.
Audit trails
Change history and activity logs to help you trace actions and support reviews.
Encryption mechanisms
Protection for data in transit and at rest, with managed key practices.
Logging and monitoring
Operational visibility, alerting, and observability for platform health and security signals.
Backup and recovery processes
Recovery planning and restore-friendly practices to support continuity and resilience.
Governance choices your institution sets. These shape day-to-day risk and compliance outcomes.
User provisioning and role assignment
Who gets access, which roles they hold, and how permissions are reviewed.
Internal retention policy
Your institution defines how long records are retained and when they should be archived.
Staff training and governance
Clear procedures, training, and periodic reviews keep policy aligned with practice.
Local procedures and approvals
Approvals, escalation paths, and accountability for sensitive actions.
Clear responsibility boundaries
This split is intentional. It reduces legal ambiguity and helps procurement teams map controls to real-world governance.
Clear, checklist-friendly answers to common security questions built for schools, RTOs, colleges, and multi-campus institutions.
FAQs
Click a question to expand. One open at a time.
Academyship uses layered protection across identity, data, and operations. That includes encryption for data in transit and at rest, role-based permissions, scoped visibility by campus and department, audit trails for sensitive actions, and continuous monitoring to detect unusual activity.
Yes. Academyship is designed to support auditability. Key actions can be logged with user identity, timestamps, and context so administrators can review activity, investigate incidents, and meet internal governance requirements.
Data is protected in transit using modern TLS standards, and protected at rest using strong encryption. Sensitive values like secrets and tokens are stored using encrypted stores, and encryption keys follow managed lifecycle controls.
Yes. Access can be managed through role-based permissions and organisation scoping. This helps ensure staff members only see what they need for their responsibilities, including support for multi-campus setups and department-level separation.
Academyship supports resilience with automated backups, versioned recovery options, and restore processes. Recovery procedures are designed to minimise downtime and protect data integrity with continuity planning for critical services.
Australian-region hosting is available on Enterprise deployments. As part of onboarding we confirm the hosting location, backup handling, and logging arrangements in writing so your governance and privacy obligations are clearly documented. Default hosting region is confirmed per deployment.
We follow a security maintenance workflow that includes regular updates, dependency and vulnerability scanning, configuration monitoring, and incident response practices. Critical fixes are prioritised based on risk and potential exposure.
Absolutely. If your institution has a vendor security questionnaire or checklist, we can provide a structured response and supporting materials based on your requirements.
Tip: Press Tab to navigate and Enter to open.
See security posture & resourcesBring your checklist. We will map Academyship controls to your requirements and show how security works across student, academic, finance, HR, and reporting workflows with real screens, real permissions, and real audit trails.
Roles, scopes, approvals, and session controls aligned to education workflows.
Trace who did what, when, across sensitive actions and exports.
A clear view of controls, responsibilities, and evidence you can take to procurement.
We map your checklist items to platform controls and workflows.
Auditability, access boundaries, retention support, and recovery posture explained plainly.
We provide platform controls. Your institution controls users, roles, and policies.
Encryption, monitoring, auditability, backups, secure boundaries.
Provisioning, role assignment, retention policy, and internal approvals.
Australian-region hosting is available on Enterprise deployments, confirmed with you during onboarding.
Pick a time and tell us what you need from the security walkthrough.
Submit opens a pre-filled email to our team so no details are stored on this page. We use them only to respond. See our Privacy Policy.
PDF overview plus questionnaire template for procurement and IT.
Submit opens a pre-filled email to our team requesting the pack. We use your details only to respond. See our Privacy Policy.