Trust
Security and data protection
Last updated: 29 September 2026
Our role
Each school using Omnis is the data controller for its pupils’, parents’ and staff’s data. Omnis is the data processor: we use that data only to provide the service, on the school’s instructions, under a Data Processing Agreement. We never sell data or use it to train AI models. Full details are in our privacy policy.
How we protect data
Signing in
Two-step sign-in (a 6-digit code by email) is compulsory for all staff. Passwords are stored only as secure hashes, sign-in attempts are rate-limited, and staff are signed out after 15 minutes without activity.
Access by role
Every page and action checks the user’s role. Pupils and parents cannot see SEND plans or other pupils’ information.
Separation between schools
Every database request is limited to the user’s own school. This is checked in regular internal audits and live tests.
Encryption
All traffic uses HTTPS with strict transport security. The database is encrypted at rest.
AI safeguards
Before any request leaves Omnis, pupil, parent and staff names are replaced with random codes, and email addresses and phone numbers are removed. The key never leaves Omnis, and nothing is sent if the check fails. Staff review everything the AI suggests before it takes effect. The AI provider does not train on this data and deletes it within 30 days.
Logging and monitoring
Significant actions, including views of SEND records, are recorded in an audit log. Errors are monitored with alerts to a named person.
Secure development
Automated code and dependency scanning, type checking, unit tests and over 450 automated end-to-end tests.
Children’s Code
Omnis has been assessed against all 15 standards of the ICO Age Appropriate Design Code, including privacy-friendly default settings and a plain-language page for pupils.
Where data is stored: our suppliers
These suppliers (sub-processors) help us run Omnis. Each is bound by data protection terms. Schools are told before we add or change a supplier.
| Supplier | What it does | Location |
|---|---|---|
| DigitalOcean | Runs the Omnis application | London, UK |
| Supabase | Database, encrypted at rest | Frankfurt, Germany |
| Anthropic | AI drafting and marking. Names are replaced with codes before anything is sent | USA (UK Addendum to the EU Standard Contractual Clauses) |
| Sentry | Error monitoring | Germany |
| Upstash | Sign-in codes and rate limiting (short-lived data) | Being confirmed |
| Resend | Sends service emails | Being confirmed |
| Wonde | Copies data from the school’s management information system | UK |
How long data is kept
Each school sets its own retention schedule in Omnis. The defaults follow the IRMS Academies Toolkit: SEND files until the pupil’s date of birth plus 31 years, and the pupil record and safeguarding files until date of birth plus 25 years. When a pupil leaves, the school downloads the pupil’s file before Omnis deletes it. When a school stops using Omnis, we return its data and then delete it, including from backups, within 90 days.
If something goes wrong
We have a written incident response plan. If a personal data breach affects a school’s data, we tell the school without undue delay and within 24 hours of becoming aware of it, so the school can meet its 72-hour deadline to notify the Information Commissioner’s Office.
Independent assurance
We have completed a Cyber Essentials self-assessment. Cyber Essentials Plus certification and an independent penetration test are planned, and we will update this page when they are complete.
Documents for schools and trusts
On request, we provide:
- supplier information to support your Data Protection Impact Assessment (DPIA)
- our own DPIA and risk register
- our Data Processing Agreement
- a summary of our incident response plan
Email privacy@omnis.education. Our terms of service are also published.