hello@ediway.co.uk

hello@ediway.co.uk

DATA SECURITY AND GOVERNANCE

Connect More of Your School.Without Giving Everyone Access to Everything.

A connected school platform should make information easier to use.

It should not make every record visible to every person.

EdiWay is designed around school-scoped, role-scoped and permission-aware access, helping schools connect learners, staff, families and authorised professionals while keeping sensitive information inside the workflows where it belongs.

SECURITY AROUND THE SCHOOL WORKFLOW

Security Should Followthe Information It Protects.

Different school records require different levels of access. The fact that information sits within one connected platform does not mean everyone sees the same thing.

PERMISSION-AWARE ACCESS

Give People the AccessTheir Responsibility Requires.

Access within EdiWay can be shaped around more than a simple user account. Relevant context can include:

Organisation

Which school is the user working within?

Role

What responsibility do they hold?

Learner

Which learner is involved?

Class

Does the user have an appropriate teaching relationship?

Family Relationship

Which parent or carer relationship is recorded?

Professional Relationship

Why does an authorised professional require access?

Information Domain

Is the information teaching, attendance, SEND, safeguarding, medical, HR or another controlled area?

Action

Is the user allowed to view, edit, export, approve or share?

This helps schools move beyond an all-or-nothing model of access.

SCHOOL-SCOPED INFORMATION

Keep Each SchoolInside the Right Boundary.

EdiWay is built around organisation-aware records and permissions. School context is used throughout the platform to help prevent information from being treated as one unrestricted shared dataset. That means school workflows can maintain clear ownership around areas such as:

Where wider organisational or trust oversight is enabled, access still needs to be explicitly governed.

Being able to oversee more than one school should not automatically provide unrestricted learner-level access across them.

SECURE USER ACCESS

Start With the PersonSigning In.

EdiWay includes account and authentication controls designed to support secure platform access. That includes foundations around:

Secure Login

Authenticate users before allowing access.

Additional Login Protection

Support stronger authentication controls, including two-factor authentication capability.

User Accounts

Maintain distinct staff, learner and family identities.

External Accounts

Support controlled professional access where enabled.

Temporary Access

Allow limited access models where appropriate.

Expiry

End access when a temporary or professional relationship should no longer remain active. 

Authentication establishes who the user is. Permissions determine what that user is allowed to do.

SENSITIVE INFORMATION

One Learner Journey.Separate Information Boundaries.

Some information needs stronger protection than ordinary classroom or administrative records. EdiWay keeps specialist domains separately permissioned.

Safeguarding

Restricted safeguarding records remain inside the dedicated safeguarding workflow.

SEND

Support information is available according to appropriate educational responsibility.

Medical and Care

Sensitive learner health and care information remains within its own access boundary.

HR

Employment information remains separate from ordinary school operational access.

Professional Casework

External collaboration remains limited to authorised learner-specific relationships.

Family Information

Parents and carers receive information appropriate to their relationship and permissions. 

Connecting these workflows does not remove their boundaries.

SAFEGUARDING INFORMATION

Keep SafeguardingMore Restricted Than Ordinary School Data.

Safeguarding information should not become generally visible simply because it relates to a learner. EdiWay's dedicated safeguarding workflow supports separately controlled records, chronology, actions, evidence and authorised sharing.

AUDIT AND ACTIVITY HISTORY

Know What Happened.Keep Important Actions Reviewable.

Schools need more than access controls. They also need accountability. EdiWay includes audit and user-activity foundations that can help authorised users understand relevant platform activity. Depending on the workflow, this can include context such as:

User

Who completed the action?

Record

What information was affected?

Action

What happened?

Time

When did it happen?

Workflow

Which area of EdiWay was involved?

History

What relevant earlier activity remains available? 

Sensitive workflows may maintain additional specialist history within their own records. Audit information helps provide accountability without becoming a substitute for good school governance.

DATA ENCRYPTION

Protect InformationWhile It Is Stored and Moving.

EdiWay's security foundations include encryption controls for stored information and information in transit. This supports protection around school data as it moves through the platform and where appropriate data is stored. Encryption is one part of the security model. It works alongside:

Security should not depend on one control alone.

BACKUPS AND RECOVERY

Protect the School RecordAgainst More Than Everyday Mistakes.

School systems need resilience as well as access control. EdiWay includes foundations around:

Data Backups

Maintain recoverable copies of appropriate platform information.

Recovery Procedures

Support restoration where required.

Record History

Preserve appropriate workflow history.

Controlled Changes

Reduce the risk of silent or uncontrolled changes in sensitive workflows.

Product Assurance

Continue testing migration, recovery and release behaviour as the platform develops. 

Backup and disaster-recovery capability forms part of EdiWay’s wider technical governance approach.

DATA MINIMISATION

Use the Information Needed.Not Everything Available.

A connected learner record can contain information from many parts of school life. That does not mean every workflow should receive all of it. EdiWay's design direction is to use the information required for the particular purpose. For example:

Teacher

Needs useful classroom and learner-support context, not the complete school record.

Cover Teacher

Needs appropriate teaching information, not confidential HR or safeguarding detail.

Parent or Carer

Needs approved information about their child, not internal school records.

External Professional

Needs information within the authorised learner relationship and purpose.

Marketplace User

Needs transaction information, not educational or safeguarding records.

Trust User

Needs appropriate oversight, not automatic unrestricted school-level access. 

Connected does not mean copied everywhere.

EXPORTS AND DOCUMENTS

Control What Leavesthe Everyday Platform View.

Information that can be viewed should not automatically be available for unrestricted export. Where supported, EdiWay can apply separate controls around:

Data Exports

Allow appropriate authorised data export.

Reports

Keep sensitive information inside suitable reporting permissions.

Documents

Control access to private or shared files.

Evidence Packs

Use dedicated workflows for higher-consequence information sharing.

Professional Sharing

Limit information to the agreed scope and authorised relationship.

Access History

Maintain appropriate evidence of access or delivery where the workflow supports it. 

The detailed information-sharing model belongs to Permissions, Consent and Information Sharing.

FAMILIES AND AUTHORISED PROFESSIONALS

Collaborate Without Openingthe Whole Learner Record.

EdiWay is designed to support collaboration beyond school staff. That includes parents and carers and, where enabled, authorised professionals. Access can remain limited according to the relationship and purpose.

Parents and Carers

Access appropriate family-facing information connected to their learner relationship.

Professionals

Work within defined learner-specific relationships.

Time-Limited Access

Professional access can be limited to the period in which it is required.

Revocation

Access can be brought to an end when the relationship changes.

Scope

Only appropriate information should be included.

The complete rules for consent, sharing purpose, access scope, expiry and revocation belong to the dedicated permissions page.

TECHNICAL ACCESS IS NOT PROFESSIONAL AUTHORITY

Running the PlatformShould Not Mean Owning Every Decision.

Technical administration and professional authority are different responsibilities.

A technical administrator may need to:

That does not automatically mean they should:

EdiWay’s wider governance model separates system administration from professional decision-making.

GOVERNED AI ACCESS

AI Should Followthe Same Information Boundaries.

EdiWay AI is designed to operate within authorised context rather than act as an unrestricted route through school data. The intended model is simple: AI should not see more information than the authorised user is permitted to use for that workflow. Where enabled, governed AI can assist with:

But AI does not create new permission. A user should not be able to ask AI to retrieve information they could not otherwise access. AI outputs remain human-reviewed.

DATA RETENTION AND RIGHTS

Keep Informationfor the Right Purpose and Period.

Schools need to manage information over time as learners, staff and professional relationships change. EdiWay includes data-retention and privacy-control foundations that can support this wider governance process. However, detailed questions about:

belong to the dedicated Privacy and Data Protection and Data Retention and Subject Rights pages. This page focuses on the security and governance controls around using the School Platform.

THE SCHOOL REMAINS IN CONTROL

Technology Supports Governance.It Does Not Replace It.

EdiWay can provide tools for controlling, recording and reviewing information. Schools still remain responsible for important organisational decisions such as:

User Roles

Who should have which responsibilities?

Staff Access

Which people need access to sensitive domains?

Policies

How should information be used within the school?

Sharing Decisions

When is information appropriately shared?

Retention

How long should particular information be retained?

Incident Response

What school procedure applies when something goes wrong?

Professional Decisions

Who has authority to make safeguarding, SEND, HR, medical or other consequential decisions?

Good information governance combines platform controls with appropriate school leadership and policy.

SECURITY ACROSS THE PLATFORM

One Security Model.Applied to Different School Workflows.

EdiWay's wider design applies security and governance across the connected School Platform.

Learner Records

Keep the canonical learner record school-scoped.

Teaching

Limit classroom access to relevant learners and responsibilities.

Attendance

Protect individual learner records while enabling authorised oversight.

SEND

Keep support information appropriately restricted.

Safeguarding

Use stronger specialist access boundaries.

HR

Keep confidential workforce information separate.

Reporting

Restrict sensitive data, exports and drill-through.

Marketplace

Keep commerce access separate from educational records.

Professional Collaboration

Use learner-specific, purposeful external access. 

Security is not a separate feature added after the workflow. It should be part of how the workflow works.

A GOVERNED ACCESS MODEL

Identify. Authorise. Access. Record. Review.

1. Identify the User

Establish who is accessing EdiWay.

2. Establish the School

Keep the action within the appropriate organisation.

3. Check the Role and Relationship

Understand why the user requires access.

4. Check the Information Domain

Keep specialist information inside the correct permission boundary.

5. Allow the Required Action

View, edit, approve, export or share only where authorised.

6. Record Important Activity

Maintain appropriate audit or workflow history.

7. Review Access

Change permissions as responsibilities and relationships change.

8. Remove Access

End access when it is no longer required.

This helps schools maintain a connected platform without turning access into a permanent entitlement.

FREQUENTLY ASKED QUESTIONS

Data Security and Governance

Is EdiWay designed for UK schools?

Yes.

EdiWay is being designed specifically around UK education workflows, learners, families, school staff and authorised professional relationships.

Does every staff member see every learner record?

No.

Access can be shaped by school, role, learner, class, relationship, domain and action.

Can teachers see safeguarding records automatically?

No.

Safeguarding records remain inside a separately controlled workflow.

Can administrators see everything?

No.

Administrative responsibility does not automatically create unrestricted access to every sensitive information domain.

Can schools use two-factor authentication?

Two-factor authentication capability forms part of EdiWay’s security controls.

Does EdiWay encrypt data?

Encryption for stored information and information in transit is represented within EdiWay’s security foundations.

Does EdiWay keep audit records?

Yes.

Audit-trail and user-activity capabilities are represented across the platform, with additional history inside specialist workflows.

Does EdiWay back up school information?

Backup and disaster-recovery capabilities form part of the current security foundation.

Can parents and carers see all information held about their child?

No.

Family access is shaped around the recorded learner relationship, permissions and information domain.

Can external professionals access learner information?

Where enabled and authorised, professionals can work through defined learner-specific relationships.

That does not provide unrestricted access to the learner record.

Can professional access expire?

Temporary and expiring access models are represented within the platform.

Can information be exported?

Appropriate data exports are supported.

Export rights remain subject to permissions and the sensitivity of the underlying information.

Does EdiWay automatically decide what information can legally be shared?

No.

The platform can enforce configured permissions and sharing controls.

The school and relevant authorised people remain responsible for the legal and professional basis of sharing.

Does EdiWay AI have access to all school data?

No.

EdiWay AI is designed to operate within permission-aware context rather than provide unrestricted access to school information.

Is EdiWay “GDPR compliant”?

EdiWay should not reduce data protection to a generic marketing badge.

The platform provides data-protection, retention, access, consent, audit and information-sharing controls, while schools remain responsible for their own data-protection obligations and how the platform is configured and used.

Has EdiWay completed independent penetration testing?

Independent penetration-testing assurance remains part of ongoing product and release assurance and should not currently be presented as complete across the whole platform.

Does using one connected platform make data less secure?

A connected platform does not need to mean unrestricted access.

EdiWay is specifically designed around information boundaries so related workflows can connect while permissions remain distinct.

CONNECTED TRUST WORKFLOWS

Security Is One Partof Wider Information Governance.

Permissions, Consent and Information Sharing

Understand who can access or receive information, for what purpose and for how long.

AI Governance

Understand how permission-aware, draft-first and human-reviewed AI is governed.

Safeguarding Boundaries

Understand where technology stops and safeguarding authority remains with people.

Privacy and Data Protection

Understand EdiWay’s wider approach to privacy responsibilities and personal information.

Data Retention and Subject Rights

Understand retention, access and individual-rights workflows.

Implementation, Migration and Product Assurance

Understand rollout, migration, testing and release assurance.

Shopping Basket