Your Data Stays in the UK

We understand that data residency matters to schools and trusts. That's why EduRisk is designed with UK data sovereignty at its core.

πŸ‡¬πŸ‡§ UK Data Residency

All customer data processed by EduRisk is hosted in the United Kingdom, specifically within the AWS London region (eu-west-2). Your risk registers, user information, and audit logs never leave UK jurisdiction.

  • βœ“ Hosted on Amazon Web Services (AWS) in the London region
  • βœ“ Data remains within UK borders at all times
  • βœ“ No transfers to third-party overseas processors
  • βœ“ Infrastructure operated by AWS under UK regulatory frameworks
πŸ‡¬πŸ‡§

AWS London (eu-west-2)

πŸ“œ GDPR & UK Data Protection

EduRisk is designed to support your compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities seriously as a data processor.

  • βœ“ Controller/Processor roles: Your school or trust remains the data controller. EduRisk (CX1 Ltd) acts as your data processor, handling data only on your instructions.
  • βœ“ Lawful processing: We process personal data solely to deliver the EduRisk service as contracted.
  • βœ“ Purpose limitation: Data is used only for risk managementβ€”never sold, shared for marketing, or used for unrelated purposes.
  • βœ“ Data retention: You control your data retention. We retain data only as long as your subscription is active, plus a reasonable wind-down period.
  • βœ“ Subject rights: We support you in responding to data subject access requests and other rights under UK GDPR.
πŸ“œ

UK GDPR Compliant

Relevant Frameworks & Guidance

We align our practices with guidance from UK regulators and education sector expectations

πŸ›οΈ

ICO Guidance

We follow guidance from the Information Commissioner's Office (ICO), the UK's independent authority for data protection. Our practices align with ICO recommendations for data processors and SaaS providers.

πŸ›‘οΈ

NCSC & Cyber Essentials

Our security practices are informed by National Cyber Security Centre (NCSC) guidance. We're working towards Cyber Essentials certification as part of our ongoing security improvement programme.

πŸŽ“

Education Sector Standards

We understand the due diligence expectations placed on schools and trusts by the DfE and ESFA. We're happy to support your supplier assurance processes with relevant documentation.

πŸ” Hosting & Infrastructure

EduRisk runs on modern, secure cloud infrastructure with multiple layers of protection.

  • βœ“ Encryption in transit: All connections use HTTPS with TLS 1.2+ encryption. Data is never transmitted in plain text.
  • βœ“ Encryption at rest: Stored data is encrypted using industry-standard encryption.
  • βœ“ Access controls: Role-based access ensures users only see what they need. Trust admins manage their own user permissions.
  • βœ“ Secure authentication: Support for strong passwords and integration with identity providers via CX1 Hub where applicable.
  • βœ“ Regular backups: Automated backups protect against data loss, with recovery procedures tested regularly.
  • βœ“ High availability: Hosted on AWS infrastructure designed for reliability and uptime.
πŸ”

Secure Infrastructure

πŸ”’ Security in Design

Security isn't an afterthoughtβ€”it's built into how we develop and operate EduRisk.

  • βœ“ CSRF protection: Cross-site request forgery protections on all forms and state-changing operations.
  • βœ“ Secure credential handling: Passwords and secrets are hashed using modern, secure algorithmsβ€”never stored in plain text.
  • βœ“ No secrets in web root: Configuration files and credentials are kept outside publicly accessible directories.
  • βœ“ Principle of least privilege: System components and user accounts have only the permissions they need.
  • βœ“ Vendor access controls: CX1 staff access to production data is limited, logged, and only for support purposes when authorised.
  • βœ“ Full audit trail: Every change to risk records is logged with timestamps and user attribution for accountability.
πŸ”’

Security by Design

DPIA & Security Questionnaires

Need to complete a Data Protection Impact Assessment or security questionnaire as part of your procurement process? We're happy to help.

Contact Us

Questions About Security?

We're transparent about how we protect your data

Can you complete our supplier due diligence questionnaire?

Yes. We understand schools and trusts have procurement requirements. Send your questionnaire to hello@edurisk.uk and we'll complete it promptly.

Do you have a Data Processing Agreement?

Yes. We provide a Data Processing Agreement (DPA) as part of our standard contract, setting out our obligations as your data processor under UK GDPR.

How long do you retain data after we leave?

Upon contract termination, we can export your data in a standard format. After a reasonable wind-down period (typically 30 days), data is securely deleted from our systems.

Who do we contact for security concerns?

For any security questions, DPIA support, or to report a concern, please email hello@edurisk.uk. We take all security matters seriously and will respond promptly.

Ready to Learn More?

We're happy to discuss our security practices in detail and support your procurement process.

Get in Touch