Security
A plain-English summary of how CoverMyClass protects school data — written for the data protection officer, IT lead, or procurement officer doing supplier due diligence. Detailed artefacts (Information Security Policy, Data Processing Agreement, breach playbook, subprocessor list, disaster-recovery summary) are available on request as part of our Trust Pack.
Version 1.0 · Last updated: May 2026 · Effective: May 2026
Summary
- Platform data is hosted in the United Kingdom.
- Each school operates in its own logically isolated workspace. Data is not shared between schools.
- Data is encrypted in transit (TLS) and at rest.
- Access is role-based, authenticated, and audit-logged. Multi-factor authentication is supported.
- The school is the data controller; CoverMyClass is the data processor under a written Data Processing Agreement.
- Confirmed personal-data breaches are notified to affected schools without undue delay, and to the ICO within 72 hours where required.
- We do not sell personal data. We do not use school or pupil data to train third-party AI models.
- Vulnerability reports: security@covermyclass.com. See Responsible disclosure.
Credentials and registrations
The formal registrations and assurances on which our security posture rests. Items marked pending are actively being acquired; those marked self-declared are based on internal evidence we can share with procurement on request.
1. Controller and processor
For data inside the platform, the school (or multi-academy trust) is the data controller. CoverMyClass is the data processor, acting on the school's documented instructions under a written Data Processing Agreement (Article 28 UK GDPR). This is the relationship UK schools expect from a compliant supplier and the basis on which we operate.
The DPA forms part of our service agreement and is shared during procurement.
2. Hosting and data residency
Platform data is stored on UK-region cloud infrastructure operated by reputable providers under written contractual safeguards. Where any subprocessor processes personal data outside the UK or the European Economic Area, we rely on an appropriate UK GDPR transfer mechanism — for example, an adequacy regulation, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — and we document the transfer in our subprocessor list.
3. Workspace isolation
Each school operates within its own private workspace. Logical separation prevents one school's data being accessed by another. Cross-tenant access by CoverMyClass personnel is restricted to a small number of authorised staff and is performed only under documented operational need — for example, customer support at the school's request, or incident response. Such access is logged.
4. Encryption
Personal data is encrypted both in transit and at rest:
- In transit: all connections to covermyclass.com and the platform are served over HTTPS using TLS 1.2 or higher. HSTS is enabled. Insecure protocols are not accepted.
- At rest: primary datastores and backups use industry-standard encryption at the storage layer.
5. Access control and authentication
Access to the platform is controlled by role-based permissions defined within each school workspace. Authentication safeguards include support for multi-factor authentication. Sessions are time-bound. Administrative and sensitive actions are recorded in an audit log that is available to schools on request.
Access to production systems by CoverMyClass personnel is restricted, least-privilege, time-bound where appropriate, and recorded. Joiner/mover/leaver controls remove access promptly when staff change role or leave.
6. Backups and resilience
The platform is operated on resilient infrastructure with routine, encrypted backups. Restoration is tested periodically. We maintain documented business continuity and disaster recovery procedures with defined recovery time and recovery point objectives. A summary of those procedures is available on request as part of our Trust Pack.
7. Incident response and breach notification
We maintain a documented incident response procedure that covers detection, triage, containment, eradication, recovery, and post-incident review. Where a personal data breach is likely to result in a risk to individuals' rights and freedoms:
- we notify affected schools without undue delay, with sufficient information to support their own regulatory obligations; and
- we notify the UK Information Commissioner's Office within 72 hours of becoming aware, in line with Articles 33 and 34 UK GDPR, where required.
We do not minimise or delay disclosure to manage commercial perception.
8. Subprocessors
We engage a small number of carefully selected third-party service providers ("subprocessors") to operate the platform — for example, UK-region cloud hosting, transactional email delivery, error monitoring, and (where applicable) payment processing. We do not share personal data with subprocessors except as needed to deliver the service, and we require all subprocessors to provide contractual protections equivalent to those we provide to schools.
A current Subprocessor Transparency Statement is available on request from privacy@covermyclass.com. We will give schools reasonable advance notice of any material change, and an opportunity to object.
9. People and culture
All staff with access to school data are subject to written confidentiality obligations, data protection and security training, and background checks proportionate to their role. We follow least-privilege principles for production access and review access rights on a regular cycle.
10. AI and machine learning
We do not use school or pupil data — including any limited pupil information entered by a school user into a cover briefing — to train, fine-tune, or evaluate third-party AI models. Where the platform uses AI features, those features are described in our service agreement and operate on a controlled basis that protects school data. We do not enable third parties to use school data for their own model training.
11. Governance and review
Our security and data-protection practices are reviewed at least annually, after significant platform changes, and following any material incident. We track open risks and remediation owners. We are committed to continuous improvement as the platform scales.
12. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability affecting CoverMyClass:
- email security@covermyclass.com with a description of the issue, the URL or component affected, steps to reproduce, and any supporting evidence;
- do not access, modify, or exfiltrate data beyond the minimum necessary to demonstrate the issue;
- do not run automated scanners that materially degrade service for other users, and do not perform social-engineering, physical, or denial-of-service testing;
- give us reasonable time to triage and remediate before any public disclosure (we aim to acknowledge within 2 working days and to provide a substantive update within 14 working days).
We will not pursue legal action against researchers acting in good faith under this policy. A machine-readable contact record is published at /.well-known/security.txt in line with RFC 9116.
13. Trust Pack — for procurement
For school DPOs, IT leads, and procurement teams, the following documents are available on request as part of our Trust Pack:
- Master Services Agreement (MSA)
- SaaS Terms and Conditions
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA)
- Information Security Policy
- Data Breach and Incident Response Policy (summary)
- Business Continuity and Disaster Recovery summary
- Subprocessor Transparency Statement
- Access Control and Role-Based Permissions Policy (summary)
- Data Retention and Deletion Policy (summary)
Email privacy@covermyclass.com with your school name and procurement timeline, and we will send the current pack within 2 working days.
14. Contact
Data protection and procurement
privacy@covermyclass.com
Vulnerability reports
security@covermyclass.com