Security & Compliance | VESPA Academy

Security & compliance

Answers before you have to ask

Everything your data protection officer, IT lead or procurement team will want to know about how VESPA handles school and student data. Published openly, not held back for a questionnaire.

Cyber Essentials certified Everything ICT approved supplier
ICO registered ZB325899 EU data store Cyber Essentials

Where your data lives

Student and staff data sits in an EU-hosted PostgreSQL database (Supabase on AWS Stockholm, eu-north-1), encrypted at rest with AES-256 and in transit with TLS 1.2 or better. Application compute runs on Vercel in the US (iad1) under SCCs. Backups stay inside the same Supabase data zone; cross-region replicas are not enabled.

Who can see it

Role-based access control enforced at the database level with row-level security on every table, not just in the application. Super admin, school admin, staff and student roles each have explicitly defined permissions.

How people sign in

Single sign-on through your own Microsoft 365 or Google Workspace tenant, so your password policy, your MFA and your conditional access rules govern every login. Email and password with optional MFA is available as a fallback.

Your legal position

Your school (or trust) is the data controller; 4Sight Education Ltd is the processor. A UK GDPR Article 28 DPA is issued at trial start, estimate acceptance or payment, incorporated into our Terms — covering sub-processors, 72-hour breach notification, audit rights, SCCs for international transfers and data return on termination. Countersignature is optional.

Getting your data out

No fee, ever, during the contract or at the end of it. CSV export from the staff dashboard at any time, and a full JSON or CSV extract on request within 30 days.

What we do with AI

AI features are advisory and only run when a user deliberately activates them (Generate, Send in chat, etc.) — not a consent tick on every click, and nothing runs silently on login. No model training on school or student data under API terms; our OpenAI org has model-improvement sharing disabled. A first name may be included for personalisation; we do not send email addresses or demographics. Schools can request AI features be disabled for their establishment.

Where we stand, honestly

No vague assurances — a straight answer on each area procurement teams typically ask about.

Area Status Detail
UK GDPR and Data Protection Act 2018 Compliant Policies published and reviewed annually
ICO registration ZB325899 Registered 4Sight Education Ltd, registered data controller
Reportable data breaches None, ever No reportable breach in our trading history
Application data store EU (Stockholm) Supabase on AWS eu-north-1 — primary student/staff data residency
Application compute US (Vercel iad1) Serverless APIs under SCCs; CDN edge elsewhere as needed
Infrastructure certification SOC 2 Type II + ISO 27001 Held by Supabase and Vercel for hosting, database and platform layers
Cyber Essentials Certified IASME-CE-060416 (2 Jul 2026–2 Jul 2027); CE Plus available for larger engagements
ISO 27001 at corporate level Not held Aligned via certified providers; direct certification on the roadmap
Uptime, last 12 months Full No customer-impacting unplanned outages

We have already been through this

Not a first-time supplier working out what a DPIA is. Our security, commercial and data-protection posture has been formally assessed by third parties and passed.

Accepted on the Everything ICT framework

We completed Everything ICT's full supplier procurement process — commercial structure, pricing transparency, data protection and service standards — and are an accepted supplier on their platform. For schools and trusts that means you can buy VESPA through a DfE-approved framework without running a separate tender, and that our terms have already been checked by someone other than us.

Full technical due diligence, completed and signed

We have completed detailed non-functional supplier reviews for academy trusts and international school groups — covering support and service models, commercial transparency, information security, privacy and regulatory compliance, architecture, integration capability, identity and SSO, and operational resilience. These run to dozens of pages and we answer them properly rather than deferring to a brochure.

Send us yours and we will turn it round in full. Recent reviews are available as references on request.

Everyone who touches your data

Aligned to our published sub-processor list (SPL-2026.08). Each is bound by contract and assessed on certification, residency and breach notification. You are notified before any material change takes effect.

Provider Role Location Assurance
Supabase Database, authentication, storage EU (Stockholm, eu-north-1) SOC 2 Type II, ISO 27001
Vercel Hosting and serverless APIs US (iad1) — SCCs SOC 2 Type II, ISO 27001
SendGrid (Twilio) Transactional email US (SCCs) Standard contractual clauses
Stripe Card payments, where used EU / US PCI DSS Level 1
OpenAI Optional portal AI features US (SCCs) SCCs; no training on customer data
Anthropic 4Sight CRM / internal ops only US / global (SCCs) Not used for school portal AI
Wonde MIS sync, where the school chooses it UK
Microsoft & Google SSO and directory sync Your own tenant / SCCs
Cookiebot, GA4, ad tags Marketing site only (consent-gated) EEA / US / global Not in the student portal

Send us your questionnaire

We have completed full non-functional due diligence for academy trusts and international school groups. Send yours over and we will turn it round properly.