Skip to content
Regulated industries · Education & EdTech

Security & Compliance for Education & EdTech

Security and compliance programmes for regulated environments, built to pass scrutiny and survive an incident.

Why it matters in education & edtech

In EdTech the product is the business, but you're also handling children's data and selling into risk-averse buyers. You have to ship great learning software and be trusted with it: CTO and CISO in one.

  • Turning pedagogy and content into a product that scales, architecture, data model and roadmap
  • Shipping AI-powered learning features (tutoring, marking, personalisation) that are genuinely useful
  • Passing the security and data-protection due diligence schools and trusts run, and protecting children's data
  • Integrating cleanly (SSO, MIS/SIS, LTI/OneRoster) and staying reliable through term-start spikes

What you get

  • Gap assessment against ISO 27001, SOC 2, NIST CSF, Cyber Essentials, or FCA expectations
  • Control design and implementation that engineers will actually adopt
  • Third-party and supply-chain risk management
  • Audit and certification support, end to end
  • Metrics and assurance that prove the controls work

Frameworks & standards

Applied AI / LLMsUK GDPR (children)Cyber Essentials

How we work in education & edtech

We've been the CTO building and scaling an EdTech product first-hand, and we own the security side too, so we help with the architecture, AI and integrations and the trust, privacy and controls that unlock school and trust deals.