Edvolve
Open navInformation & Platform Security Policy Security built into every stage.
Last updated 5th August 2026
1. Purpose
Protecting the confidentiality, integrity and availability of information is fundamental to the design, development and operation of Edvolve.
Information security underpins every stage of the platform lifecycle, supporting schools, academies and multi-academy trusts in using Edvolve with confidence. Security is considered from the earliest stages of product planning through to software development, deployment, maintenance and continual improvement.
This policy explains the principles, governance arrangements and organisational measures that help protect the Edvolve platform, the services it delivers and the information processed on behalf of subscribing organisations.
It should be read alongside the Edvolve Trust & Compliance Framework and the Data Protection & Children's Privacy Policy, which together form part of our wider approach to security, privacy and compliance.
Our objective is to maintain a secure, resilient and reliable platform that supports education without introducing unnecessary complexity for schools or compromising the protection of the information entrusted to us.
2. Information Security Principles
Information security is not treated as a standalone activity or a feature added at the end of development. Instead, it forms part of the decisions made throughout the design, development, operation and ongoing improvement of the Edvolve platform.
Our approach is guided by a number of established security principles that help ensure security remains proportionate, practical and effective.
Security by Design
Security considerations are incorporated throughout the software development lifecycle, from initial planning and architecture through to deployment, maintenance and future development. New functionality is designed with security in mind from the outset rather than being introduced retrospectively.
Defence in Depth
No individual security measure is relied upon in isolation. Multiple technical and organisational controls work together to reduce risk and help protect the platform against a wide range of potential threats.
Least Privilege Access
Users are provided with access only to the information and functionality required to perform their responsibilities. Permissions are allocated according to organisational roles and can be updated as responsibilities change.
Secure by Default
Default platform settings are designed to support secure operation wherever reasonably possible. Security should not depend upon additional configuration by schools before appropriate protection is provided.
Risk-Based Decision Making
Information security decisions are informed by the potential impact on the confidentiality, integrity and availability of information, allowing resources and controls to be applied where they are most effective.
Continuous Monitoring
Platform performance, operational health and security events are monitored to support the early identification of issues and enable appropriate investigation where required.
Continuous Improvement
Information security is continually reviewed as technology, operational requirements and the wider threat landscape evolve. Lessons learned, customer feedback and changes in recognised security guidance help inform future improvements to the platform.
Together, these principles provide the foundation upon which the security of the Edvolve platform is designed, maintained and continually strengthened.
3. Security Governance
Information security forms an integral part of AppyHive Ltd's governance framework and is supported by documented policies, defined responsibilities and ongoing operational oversight.
Responsibility for protecting the Edvolve platform extends across the organisation and is considered throughout product development, operational management and customer support. Security decisions are not isolated to technical implementation but form part of wider business governance, helping ensure that risks are identified, assessed and managed appropriately.
Our governance approach includes:
- Maintaining documented information security policies and procedures;
- Reviewing security risks as part of platform development and operational change;
- Considering security throughout the software development lifecycle;
- Applying appropriate technical and organisational measures to reduce identified risks;
- Monitoring the effectiveness of security controls;
- Managing security updates and operational improvements;
- Responding appropriately to security incidents where they occur; and
- Reviewing this policy and associated documentation on a regular basis.
Security governance also supports compliance with applicable UK legislation and recognised regulatory guidance while promoting a culture of continual improvement across the platform.
Where significant changes are proposed to the platform or supporting services, security considerations form part of the planning, assessment and implementation process to help ensure that appropriate safeguards continue to be maintained.
Information security is therefore regarded as an ongoing responsibility rather than a one-time exercise, supporting the long-term resilience, reliability and trustworthiness of the Edvolve platform.
4. Platform Security
The Edvolve platform is designed to provide a secure and reliable environment for schools, academies and multi-academy trusts, supporting the day-to-day management of information while helping to protect the confidentiality, integrity and availability of the services it provides.
Security is considered throughout the platform architecture and operational environment, with multiple complementary safeguards working together to reduce risk. This layered approach helps ensure that the effectiveness of the platform does not depend upon any single security control.
Platform security includes measures that support:
- Secure user authentication and access management;
- Role-based permissions across platform functionality;
- Protection of information during transmission;
- Controlled administrative access;
- Security monitoring and operational oversight;
- Regular platform maintenance and security updates;
- Secure backup procedures; and
- Platform resilience and service continuity.
These measures are reviewed periodically as the platform evolves, helping ensure that security continues to support changing operational requirements, recognised industry guidance and the evolving cyber security landscape.
5. Identity & Access Management
Access to the Edvolve platform is controlled through authenticated user accounts, role-based permissions and the principle of least privilege. Together, these measures help ensure that users can only access the information and functionality appropriate to their responsibilities.
Permissions are designed to reflect the operational structure of each subscribing organisation, allowing schools to allocate appropriate levels of access across leadership teams, teaching staff, administrative personnel, support staff, parents and students.
Our approach to identity and access management supports:
- Authentication before access is granted;
- Role-based permissions aligned to organisational responsibilities;
- Administrative control over user account creation, modification and removal;
- The ability to review and update permissions as roles change; and
- Measures intended to reduce the risk of unauthorised access.
Schools remain responsible for managing user accounts and permissions within their own organisation, while AppyHive Ltd maintains the underlying platform controls that support secure authentication and access management.
Identity and access management forms an important part of our wider Security by Design approach, helping protect both platform functionality and the information processed on behalf of subscribing organisations.
6. Encryption & Secure Communications
Protecting information while it is transmitted between users and the Edvolve platform forms an important part of our overall security approach.
Industry-recognised encryption is used to help protect communications between supported devices and the platform, reducing the risk of information being intercepted or altered during transmission.
Encryption supports the protection of:
- User authentication;
- Information exchanged between supported devices and the platform;
- Documents, files and multimedia shared through platform features;
- Administrative access to authorised platform services; and
- Other communications where appropriate to support secure platform operation.
Encryption is not considered a standalone security measure. Instead, it forms part of a wider combination of technical and organisational controls that work together to support the confidentiality and integrity of information throughout the platform.
As recognised security standards continue to evolve, encryption practices are reviewed as part of our ongoing commitment to maintaining an appropriate level of protection.
7. Secure Development & Change Management
Security is considered throughout the software development lifecycle, helping ensure that new functionality and platform improvements are introduced in a controlled and responsible manner.
From the earliest stages of planning, significant changes are considered not only for their functional requirements, but also for their potential impact on security, privacy and operational resilience.
Our development approach includes:
- Considering security requirements during feature planning and design;
- Assessing potential risks associated with significant platform changes;
- Functional and security testing prior to deployment;
- Controlled release and deployment procedures;
- Ongoing maintenance and improvement following release; and
- Monitoring the operational impact of significant changes where appropriate.
This approach helps maintain the stability, reliability and security of the Edvolve platform while supporting the continual development of new functionality.
Security is therefore regarded as an ongoing consideration throughout development rather than an activity performed only before software is released.
8. Infrastructure & Platform Resilience
Edvolve is designed to operate within a resilient cloud environment that supports the secure delivery of services to schools, academies and multi-academy trusts.
Platform resilience is achieved through a combination of technical controls, operational procedures and ongoing maintenance activities that help support service availability and minimise disruption.
Our approach includes measures that support:
- Platform availability and operational continuity;
- Secure backup procedures;
- Controlled maintenance activities;
- Capacity planning and performance monitoring;
- Planned software updates; and
- Recovery planning in the event of unexpected disruption.
Operational resilience is reviewed as part of the continued development of the platform, helping ensure that services remain reliable as customer requirements and operational demands evolve.
While no online service can guarantee uninterrupted availability, AppyHive Ltd is committed to maintaining a resilient platform supported by appropriate planning, monitoring and continual improvement.
9. Vulnerability & Patch Management
Maintaining the security of the Edvolve platform requires vulnerabilities to be identified, assessed and addressed in a timely and controlled manner.
Potential vulnerabilities may be identified through platform monitoring, routine maintenance, software updates, recognised security guidance, responsible disclosure or other appropriate sources.
Where security issues are identified, they are assessed according to the potential risk they present to the confidentiality, integrity and availability of the platform and the information it processes.
Our approach includes:
- Reviewing potential vulnerabilities using a risk-based approach;
- Applying security updates where appropriate;
- Prioritising remediation according to risk and operational impact;
- Testing significant updates before deployment where appropriate; and
- Monitoring the effectiveness of corrective actions following implementation.
Security updates form part of the ongoing maintenance of the platform and contribute to our wider commitment to Security by Design and continual improvement.
10. Monitoring & Logging
Operational monitoring supports the continued security, stability and performance of the Edvolve platform.
Monitoring activities help identify service issues, unusual operational behaviour and potential security events, enabling appropriate investigation and response where required.
Logging also supports the operation of the platform by providing information that may assist with:
- Diagnosing operational issues;
- Investigating suspected security incidents;
- Supporting system maintenance;
- Identifying service improvements; and
- Maintaining the integrity of platform operations.
Monitoring and logging are undertaken for operational and security purposes and form part of our wider governance framework.
Information generated through monitoring activities is handled appropriately and only accessed where necessary by authorised personnel fulfilling their operational responsibilities.
11. Business Continuity & Disaster Recovery
Maintaining the continued availability of the Edvolve platform is an important part of our operational responsibilities.
Business continuity planning supports our ability to continue providing services during unexpected operational disruption, while disaster recovery arrangements help support the timely restoration of platform services where recovery is required.
Our approach includes consideration of:
- Operational resilience;
- Secure backup arrangements;
- Recovery procedures;
- Service restoration planning;
- Ongoing operational review; and
- Lessons learned following significant operational events.
Business continuity and disaster recovery arrangements are reviewed periodically to help ensure they remain appropriate for the continued operation of the platform.
Although every reasonable effort is made to minimise disruption, recovery activities will always prioritise the protection of information, platform integrity and the safe restoration of services.
12. Supplier & Third-Party Security
AppyHive Ltd carefully considers the security of third-party services that support the operation and delivery of the Edvolve platform.
Before introducing third-party providers that may support platform services, appropriate consideration is given to their suitability, security arrangements and the role they perform within the wider service.
Our approach includes:
- Assessing the suitability of third-party providers before use;
- Applying appropriate contractual and confidentiality obligations where applicable;
- Limiting third-party access to only what is necessary to provide their service;
- Reviewing supporting providers as operational requirements evolve; and
- Maintaining transparency regarding third-party services where appropriate.
Where third-party providers process personal information on behalf of AppyHive Ltd, appropriate contractual safeguards are implemented in accordance with applicable UK data protection legislation.
Further information regarding approved sub-processors and supporting infrastructure is available within the Edvolve Trust Centre.
13. Security Awareness
Information security depends not only on technology, but also on the people responsible for developing, supporting and operating the platform.
AppyHive Ltd promotes a culture in which security forms part of everyday operational decision-making rather than being considered only during technical implementation.
Personnel responsible for the operation of the Edvolve platform are expected to:
Follow documented security procedures;
- Protect confidential information appropriately;
- Report suspected security concerns promptly;
- Exercise appropriate care when handling customer information; and
- Support the continual improvement of security practices across the organisation.
By embedding security awareness into day-to-day responsibilities, we aim to reduce operational risk while supporting the continued protection of the platform and the information entrusted to us.
14. Continuous Improvement
Information security is not regarded as a fixed objective but as an ongoing process that evolves alongside technology, legislation, customer expectations and the wider cyber security landscape.
As the Edvolve platform continues to develop, security controls, operational procedures and governance arrangements are reviewed regularly to help ensure they remain effective and proportionate.
Continual improvement is supported through:
- Periodic review of security policies and procedures;
- Assessment of operational risks;
- Consideration of customer feedback where relevant;
- Monitoring changes in recognised security guidance;
- Reviewing lessons learned from operational events; and
- Ongoing development of the Edvolve platform.
This commitment helps ensure that information security continues to develop alongside the platform while supporting the needs of schools, academies and multi-academy trusts.
15. Security Reporting
AppyHive Ltd encourages the responsible reporting of potential security issues affecting the Edvolve platform.
If a customer, school, security researcher or other individual believes they have identified a potential vulnerability or security concern, they are encouraged to report it using the published contact details available within the Edvolve Trust Centre.
All legitimate reports are reviewed appropriately and investigated in accordance with our internal security procedures.
Where a genuine security issue is identified, appropriate action will be taken to assess the potential impact, reduce any identified risk and implement corrective measures where necessary.
Responsible reporting supports the continued improvement of the platform and contributes to maintaining a secure environment for all subscribing organisations.
16. Policy Review & Version Control
This policy forms part of the Edvolve Trust Centre and supports our wider Trust & Compliance Framework.
It is reviewed at least annually, or sooner where significant changes to the platform, supporting infrastructure, applicable legislation or recognised security guidance make earlier review appropriate.
Document revisions help ensure the policy continues to reflect the way the Edvolve platform is designed, developed, operated and maintained.
The latest approved version of this policy will always be made available through the Edvolve Trust Centre.
•••
•••••