Every aspect of SENtiment is designed to protect sensitive SEND data in compliance with UK GDPR and DPA 2018.
Only authorised roles — admins, SENCOs and teachers — can generate or download any report. Parents and transport staff cannot access sensitive exports.
Users can only ever access children and records belonging to their own school. Cross-school data access is blocked at the API level.
All data exports include GDPR confidentiality notices, are stamped with the exporting user's name, and are restricted to authorised recipients only.
Data handling follows UK GDPR and DPA 2018 standards. Every report includes handling warnings appropriate to the sensitivity of SEND data.
All data is encrypted using TLS 1.3 in transit and AES-256 at rest. Keys are managed using industry-standard practices.
The platform undergoes regular penetration testing and security reviews to ensure your data remains protected against emerging threats.
✓ UK GDPR · DPA 2018 · SEND Code of Practice compliant
Questions about our security practices? Contact our team