How we look after your school's data
GrantMe exists to handle school data responsibly. Below is the list of controls we actually run.
Your data stays in Australia
- Account data is hosted and processed in Sydney, replicated across multiple independent data centres within that region.
- AI processing runs in Australia (the AWS Sydney region).
- Our AI provider is contractually prohibited from training models on customer data.
What we don't collect
- No student data of any kind
- No health information
- No financial account details
- No biometric data
None of it is needed to do the job, so we don't ask for it.
How access is protected
- Multi-factor authentication on every account. There is no password-only access.
- Role-based access control, so staff only see what their role allows.
- Every school's data is isolated at the database layer.
- Full audit logging of account activity.
How the platform is defended
- Encryption in transit and at rest.
- Cloudflare's always-on network protection sits in front of the service, filtering malicious and denial-of-service traffic at the edge before it reaches us.
- Rate limiting and request validation on every request, plus per-school data isolation enforced at the database layer. We don't yet run a dedicated application-layer web application firewall. Upgrading to one is on our roadmap.
- Security patches on a documented severity-based schedule: within 48 hours where a vulnerability is actively being exploited, and within 14 days of disclosure otherwise.
- Dependency and vulnerability scanning on every code change, with high and critical findings in production dependencies blocking the build, plus continuous automated scanning by an independent third-party security platform.
- A penetration test by an accredited external provider will be completed by 30 June 2027, and at least annually after that. We have not yet had one. This page will be updated when that changes.
If something goes wrong
- Documented incident response, business continuity and disaster recovery plans, reviewed at least annually.
- Affected schools notified as soon as possible: an initial notification within 48 hours of us becoming aware, with full details as they emerge.
- Daily backups retained for 30 days, point-in-time recovery for the previous 7 days, and backup restoration tested every six months.
Standards we work to
We build against recognised standards: the Australian Privacy Act 1988, OWASP secure development practices, and the expectations set out in the Safer Technologies 4 Schools (ST4S) framework, which we use to guide our internal security and privacy program. GrantMe has not yet completed an ST4S assessment. We'll update this page when that changes.