← Back

Security

How we protect your data and how to reach us about security

Last reviewed: August 2026 — Version 1.1

1. Our approach

Learning Lens is designed for schools and local authorities who expect clear technical and organisational controls around staff professional data. This page summarises our security posture and compliance roadmap. It does not replace the Privacy Policy or Data Processing Agreement, which set out the legal terms of processing.

2. Technical controls

  • Encryption: Data in transit uses TLS; data at rest in our primary database is encrypted (AES-256) via our hosting provider in the EU (Frankfurt).
  • Isolation: School-by-school data isolation is enforced in the database (Row Level Security), not only in the application. Role-based access within each school limits what each user can see.
  • Authentication: Sessions and identity are managed with industry-standard token-based authentication.
  • Hosting: The application and API routes that process personal data run on infrastructure with documented certifications; see the sub-processor list in our Data Processing Agreement for detail.

3. Organisational measures

  • No routine access to customer data by Learning Lens staff; any access for support is limited, logged, and only when needed.
  • Dependencies are kept current; security-relevant changes are triaged and deployed through our normal release process.
  • We maintain records suitable for demonstrating UK GDPR processor obligations and cooperate with our customers on their own assurance activities where reasonable.

4. Compliance and assurance

We align our practice with common expectations for school-facing SaaS (UK GDPR, Data Protection Act 2018, and the NCSC’s cloud security principles for context). The authoritative list of sub-processors, locations, and transfer mechanisms is in the DPA, Schedule 1.

Roadmap (not yet certified): We are working towards Cyber Essentials certification; we do not display a Cyber Essentials badge until the certificate is issued. Further assurance (e.g. Cyber Essentials Plus, independent penetration testing, SSO) is on our product roadmap and will be reflected here and on our About page as they are delivered.

For council information governance teams: a DPIA support pack is available for your council's review — a screening assessment, a pre-populated Data Protection Impact Assessment in ICO format, a security architecture summary, a sub-processor register, a staff privacy notice insert, and a mapping against council cloud-service criteria. Email jamie@mylearninglens.app and we will send the pack the same week.

5. Vulnerability disclosure

If you believe you have found a security vulnerability in Learning Lens, please report it in confidence. We will acknowledge receipt, investigate in good faith, and coordinate on disclosure with you.

Contact: jamie@mylearninglens.app

Please do not use this address for general product or sales enquiries — use the contact details in our Privacy Policy for those.

6. Changes to this page

We will update this page when our security or assurance posture changes materially. The date at the top of the page is updated when the content is meaningfully revised.

7. General contact

For data protection and privacy questions: jamie@mylearninglens.app (see the Privacy Policy).