Trust

Security and data protection

Last updated: 29 September 2026

Our role

Each school using Omnis is the data controller for its pupils’, parents’ and staff’s data. Omnis is the data processor: we use that data only to provide the service, on the school’s instructions, under a Data Processing Agreement. We never sell data or use it to train AI models. Full details are in our privacy policy.

How we protect data

Signing in

Two-step sign-in (a 6-digit code by email) is compulsory for all staff. Passwords are stored only as secure hashes, sign-in attempts are rate-limited, and staff are signed out after 15 minutes without activity.

Access by role

Every page and action checks the user’s role. Pupils and parents cannot see SEND plans or other pupils’ information.

Separation between schools

Every database request is limited to the user’s own school. This is checked in regular internal audits and live tests.

Encryption

All traffic uses HTTPS with strict transport security. The database is encrypted at rest.

AI safeguards

Before any request leaves Omnis, pupil, parent and staff names are replaced with random codes, and email addresses and phone numbers are removed. The key never leaves Omnis, and nothing is sent if the check fails. Staff review everything the AI suggests before it takes effect. The AI provider does not train on this data and deletes it within 30 days.

Logging and monitoring

Significant actions, including views of SEND records, are recorded in an audit log. Errors are monitored with alerts to a named person.

Secure development

Automated code and dependency scanning, type checking, unit tests and over 450 automated end-to-end tests.

Children’s Code

Omnis has been assessed against all 15 standards of the ICO Age Appropriate Design Code, including privacy-friendly default settings and a plain-language page for pupils.

Where data is stored: our suppliers

These suppliers (sub-processors) help us run Omnis. Each is bound by data protection terms. Schools are told before we add or change a supplier.

SupplierWhat it doesLocation
DigitalOceanRuns the Omnis applicationLondon, UK
SupabaseDatabase, encrypted at restFrankfurt, Germany
AnthropicAI drafting and marking. Names are replaced with codes before anything is sentUSA (UK Addendum to the EU Standard Contractual Clauses)
SentryError monitoringGermany
UpstashSign-in codes and rate limiting (short-lived data)Being confirmed
ResendSends service emailsBeing confirmed
WondeCopies data from the school’s management information systemUK

How long data is kept

Each school sets its own retention schedule in Omnis. The defaults follow the IRMS Academies Toolkit: SEND files until the pupil’s date of birth plus 31 years, and the pupil record and safeguarding files until date of birth plus 25 years. When a pupil leaves, the school downloads the pupil’s file before Omnis deletes it. When a school stops using Omnis, we return its data and then delete it, including from backups, within 90 days.

If something goes wrong

We have a written incident response plan. If a personal data breach affects a school’s data, we tell the school without undue delay and within 24 hours of becoming aware of it, so the school can meet its 72-hour deadline to notify the Information Commissioner’s Office.

Independent assurance

We have completed a Cyber Essentials self-assessment. Cyber Essentials Plus certification and an independent penetration test are planned, and we will update this page when they are complete.

Documents for schools and trusts

On request, we provide:

  • supplier information to support your Data Protection Impact Assessment (DPIA)
  • our own DPIA and risk register
  • our Data Processing Agreement
  • a summary of our incident response plan

Email privacy@omnis.education. Our terms of service are also published.