Security

Enterprise-grade security
built in from day one

Every aspect of SENtiment is designed to protect sensitive SEND data in compliance with UK GDPR and DPA 2018.

Role-based access controls

Only authorised roles — admins, SENCOs and teachers — can generate or download any report. Parents and transport staff cannot access sensitive exports.

School-level data isolation

Users can only ever access children and records belonging to their own school. Cross-school data access is blocked at the API level.

Secure, auditable exports

All data exports include GDPR confidentiality notices, are stamped with the exporting user's name, and are restricted to authorised recipients only.

GDPR-compliant by design

Data handling follows UK GDPR and DPA 2018 standards. Every report includes handling warnings appropriate to the sensitivity of SEND data.

Encrypted in transit & at rest

All data is encrypted using TLS 1.3 in transit and AES-256 at rest. Keys are managed using industry-standard practices.

Regular security audits

The platform undergoes regular penetration testing and security reviews to ensure your data remains protected against emerging threats.

✓ UK GDPR · DPA 2018 · SEND Code of Practice compliant

Questions about our security practices? Contact our team