Security & Certifications Summary
This summary supports your DPIA risk assessment. Full detail is at iantz.com/security.
Certifications held
| Standard / certification | Status | Relevance |
|---|---|---|
| Cyber Essentials Plus | Certified (2026) | UK Government-backed baseline; independently verified |
| ICO registration | ZC093007 | IANTZ LIMITED registered with the ICO |
| UK GDPR / DPA 2018 | Compliant programme | Privacy policy, DPAs, DPIA support, breach procedures |
| PCI-DSS | Via Stripe (Level 1) | Card data not stored by iAntz; tokenised payments only |
| WCAG 2.2 AA | Designed to | Accessibility for parents and staff |
ISO standards — practices aligned
Unless certified above, the following means our policies and controls are aligned with these ISO/IEC standards — not that iAntz holds third-party ISO certification.
| Standard | Focus | Relevance to iAntz |
|---|---|---|
| ISO/IEC 27001 | Information security management | ISMS: risk, policies, access control, incidents, suppliers |
| ISO/IEC 27002 | Security controls | Control catalogue for platform and operations |
| ISO/IEC 27701 | Privacy information management | UK GDPR programme, DPIAs, data subject rights, ROPA support |
| ISO/IEC 27017 | Cloud security | AWS and Cloudflare shared-responsibility controls |
| ISO/IEC 27018 | PII in public cloud | Pupil and parent data safeguards in cloud hosting |
| ISO/IEC 42001 | AI management | AI governance, risk, and human oversight for assistant features |
AWS (our primary cloud provider) is certified to ISO 27001, 27017, and 27018 at the infrastructure layer.
Technical measures (summary)
- Hosting: Core application data in AWS UK (London); delivery via Cloudflare
- Encryption in transit: TLS 1.3 (TLS 1.2 minimum for legacy)
- Encryption at rest: AES-256 where supported; keys via AWS KMS with rotation
- Secrets: AWS Secrets Manager; no secrets in source code
- Access control: Role-based access, least privilege, MFA for privileged access
- Authentication: Passkeys, email/password, magic links, social sign-in, TOTP MFA
- Payments: No full card numbers stored; Stripe-hosted card capture
- Logging: Audit logs for user and admin actions
- Monitoring: SIEM, error monitoring (Sentry), automated alerting
- Testing: Annual CREST-accredited independent penetration testing; SAST/DAST in CI/CD
- Backups: Automated encrypted backups; tested disaster recovery
Organisational measures
- Documented incident response plan; ICO notification within 72 hours where required
- Staff security awareness training
- DBS checks for personnel with access to children's data
- DPIAs conducted for high-risk processing including children's data and AI use cases
- Processor due diligence and data processing agreements
Business continuity
| Metric | Target |
|---|---|
| Uptime | 99.99% |
| Recovery Time Objective (RTO) | < 4 hours |
| Recovery Point Objective (RPO) | < 1 hour |
AI and children's data
- No customer PII used to train public AI models (contractually enforced)
- AI does not initiate payments or move funds
- Human oversight for significant operational decisions
- Pupil data not used for marketing or behavioural advertising
Further assurance
School DPOs may request additional due diligence documentation: [email protected]
Cyber Essentials certificate: verify online