Cyber Essentials Plus
Independently verified UK Government-backed certification (2026).
A comprehensive overview of our standards, frameworks, and security practices to protect your data and our platform.
The controls schools and DPOs ask about first — hosting, payments, testing, and how we handle children's data.
Independently verified UK Government-backed certification (2026).
Core application data on AWS in London, with Cloudflare for delivery and protection.
Card payments via Stripe (PCI-DSS Level 1). iAntz does not store full card details.
Independent testing annually, after major changes, with retest on critical findings.
Defined RTO and RPO, with 24/7 monitoring and a public status page.
DPIAs for high-risk processing. No customer PII used to train AI models.
| Certification | Status | Scope |
|---|---|---|
| Cyber Essentials Plus | Certified (2026) | UK Government-backed cybersecurity baseline with independent technical verification |
| ICO registration | ZC093007 | IANTZ LIMITED registered with the UK Information Commissioner's Office |
| PCI-DSS Level 1 | Via Stripe (processor) | Card payments; iAntz does not store full cardholder data |
Our security and privacy programme is aligned with the following ISO/IEC standards. These guide our policies, controls, and risk management. Unless stated as certified above, alignment does not mean third-party ISO certification of iAntz.
| Standard | Focus | How we apply it |
|---|---|---|
| ISO/IEC 27001 | Information security management (ISMS) | Risk assessments, security policies, access control, incident response, supplier management |
| ISO/IEC 27002 | Security controls catalogue | Control selection and implementation across the platform and operations |
| ISO/IEC 27701 | Privacy information management (PIMS) | UK GDPR programme, DPIAs, data subject rights, processor/controller documentation |
| ISO/IEC 27017 | Cloud security controls | Shared responsibility, tenant isolation, and cloud-specific controls for AWS and Cloudflare |
| ISO/IEC 27018 | PII protection in public cloud | Safeguards for pupil and parent data hosted in cloud infrastructure |
| ISO/IEC 42001 | AI management systems | Governance, risk assessment, and human oversight for AI-assisted features |
Core cloud infrastructure (AWS) is operated by a provider certified to ISO 27001, 27017, and 27018. See our data protection pack for school due diligence documents.
| Standard/Framework | Description |
|---|---|
| NIS2 | Baseline measures for risk management, incidents, supply chains, and resilience (UK NIS framework) |
| AWS Well-Architected Framework | Secure, reliable cloud architecture across AWS Well-Architected pillars |
| UK GDPR / DPA 2018 | Data protection compliance programme; privacy policy, DPAs, and DPIA support |
| WCAG 2.2 AA | Accessibility standard for parents, staff, and administrators |
iAntz holds Cyber Essentials Plus certification, the UK Government-backed scheme that includes independent technical verification and helps organisations guard against the most common cyber threats. This independently verified certification demonstrates our commitment to fundamental cybersecurity hygiene, covering secure configuration, access control, malware protection, patch management, and firewalls.
View certificate| State | Encryption Standard |
|---|---|
| In Transit | TLS 1.3 enforced for all connections. TLS 1.2 supported only for legacy compatibility. HSTS enabled. Perfect Forward Secrecy enforced. |
| At Rest | AES-256-GCM for all stored data. Encryption keys segregated by environment and rotated automatically. |
All data encrypted using AES-256-GCM
All user actions and system events captured in tamper-proof storage:
What We Log:
Immutability Benefits:
Protection against all major web application security risks:
Automated security analysis integrated into development workflow:
Centralised security visibility and threat detection:
| Capability | Description |
|---|---|
| Log Aggregation | Real-time collection and normalisation from all systems |
| Correlation Engine | Pattern identification across related events |
| Threat Detection | Behavioural analytics and threat intelligence |
| Automated Alerting | Immediate notifications for security events |
| Incident Timeline | Complete event reconstruction for investigations |
| Compliance Reporting | Audit-ready reports for regulatory requirements |
| Objective | Target | Description |
|---|---|---|
| RTO (Recovery Time Objective) | < 4 hours | Maximum time to restore full service following a critical failure |
| RPO (Recovery Point Objective) | < 1 hour | Maximum acceptable data loss window; backups run at least hourly |
| Uptime Target | 99.99% | Equates to less than 52 minutes downtime per year |
Live service status: status.iantz.com
We are committed to making iAntz accessible to everyone, including users with disabilities. Our platform is designed and developed to meet WCAG 2.2 Level AA standards, ensuring an inclusive experience for all parents, school staff, and administrators.
| Principle | What We Do |
|---|---|
| Perceivable | Text alternatives for images, captions for media, sufficient colour contrast, and content that adapts to different screen sizes |
| Operable | Full keyboard navigation, no time-limited interactions, clear focus indicators, and skip navigation links |
| Understandable | Clear language, consistent navigation, predictable behaviour, and helpful error messages with suggestions |
| Robust | Semantic HTML, ARIA attributes, compatibility with assistive technologies including screen readers |
iAntz processes data relating to children, including identities, financial transaction history, and potentially sensitive inferences such as Free School Meal status. We treat this data with the highest level of care.
Access to pupil and parent data is logged. Unusual access patterns (for example, out-of-scope lookups or bulk activity) are reviewed by our security team.
Roles are pre-modelled around how schools actually operate — not generic IT roles:
| Category | Measures |
|---|---|
| Standards & Frameworks | Certified: Cyber Essentials Plus (2026). Registered: ICO ZC093007. Aligned: ISO/IEC 27001, 27002, 27701, 27017, 27018, 42001. Also: UK GDPR, NIS2-aligned, WCAG 2.2 AA (designed to), PCI-DSS via Stripe |
| Data Residency | Core platform on AWS UK (London); website and app via Cloudflare; subprocessors under DPAs with appropriate safeguards |
| Infrastructure | AWS Well-Architected, Infrastructure as Code, environment segregation |
| Encryption | AES-256-GCM at rest; TLS 1.3 enforced in transit; HSTS; Perfect Forward Secrecy |
| Key Management | AWS KMS with automatic rotation; IAM separation of duties; per-environment key isolation |
| Secrets Management | AWS Secrets Manager; no secrets in code repositories; runtime injection only |
| Access Control | RBAC, Least Privilege, Just-in-Time Access, Default-Deny |
| Authentication | Passkeys, email/password, magic links, social sign-in (Google, Apple, Microsoft, Facebook), TOTP MFA, re-auth for sensitive actions |
| Payments & PCI-DSS | No card data stored; tokenised workflows via Stripe (PCI-DSS Level 1); immutable transaction ledger; automated reconciliation; fraud controls |
| Audit & Logging | Immutable Audit Logs; full action tracking; transaction anomaly detection |
| Development Security | OWASP Top 10, CI/CD Security Scanning, Secure Coding, Secrets Detection |
| Vulnerability Management | Annual + change-triggered CREST-accredited pen testing; external retest on critical findings; continuous automated scanning; dependency monitoring |
| Monitoring & Detection | SIEM, 24/7 Threat Detection, Real-time Alerting, Behaviour Analytics |
| Business Continuity | RTO <4h, RPO <1h; Automated Backups; Disaster Recovery Tested Quarterly |
| Safeguarding & Children's Data | DPIAs; enhanced insider-access logging; school role pre-modelling; MAT central policy enforcement; no ad trackers; no data sold or shared commercially |
| Data Retention & Deletion | UK education-aligned schedules; cryptographic erasure; GDPR deletion request fulfilment |
| AI Governance | ISO/IEC 42001 aligned; no PII used to train models; data minimisation; DPIAs for AI use cases |
| Responsible Disclosure | Public policy; compliance@iantz.com; 2-day acknowledgement SLA |
| Accessibility | WCAG 2.2 AA; keyboard navigation; screen reader support; reduced motion |
| Staff Security | DBS Checks, Security Training, Confidentiality Agreements, Insider Threat Controls |
Third-party providers we use to deliver the platform securely. All are vetted and bound by data processing agreements.
At iAntz, we are committed to transparency about how we handle your data. We work with carefully selected third-party service providers (data processors) to deliver our platform securely and efficiently. All processors are vetted for their security practices and compliance with UK data protection regulations.
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | API, database, storage, email (SES), managed AI services, and backend services | Application data, logs, backups | UK (London) primary |
| Cloudflare | Website and app delivery, CDN, DDoS protection, WAF, and bot protection | Web traffic, access logs | UK/EU with appropriate safeguards |
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Google, Apple, Microsoft, Facebook | Social sign-in (OAuth) where users choose these providers | User identifiers, email address, basic profile information | Provider-dependent; governed by DPAs |
| Google (Firebase) | Push notifications only (FCM) | Device tokens | Provider-dependent; governed by DPAs |
iAntz does not store, process, or transmit full cardholder data. All payments are processed via PCI-DSS Level 1 certified providers using tokenised workflows and hosted checkout pages. Card numbers, CVVs, and full PANs never enter our systems. This minimises our PCI-DSS scope and eliminates the most significant category of payment data risk.
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Stripe | Card payments, wallet top-ups, and refunds | Payment metadata, transaction records (card data handled by Stripe) | UK/EU |
Immutable ledger & reconciliation:
Fraud & abuse controls:
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon SES | Transactional and service-related email | Email addresses, message content | UK/EU |
| Twilio | SMS and WhatsApp messaging (where enabled by schools) | Phone numbers, message content | UK/EU with appropriate safeguards |
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Wonde | MIS integration and pupil data synchronisation (as authorised by schools) | Pupil identifiers, names, class memberships | UK |
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| HubSpot | CRM, customer support, and marketing (with consent where required) | Contact information, communication history, support enquiries | EU hosting |
| Google (Analytics) | Website measurement on iantz.com. The analytics cookie is set only after consent. Cookieless pings are sent when consent is absent or refused. Advertising cookies and a hashed contact-form email are used only after consent. | Pages viewed, device and browser, and a cookie identifier only after consent. Contact form contents are not sent. | United States, with Google’s data processing terms |
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Sentry | Error monitoring and platform stability | Technical logs, minimised personal data | EU |
AI-assisted features use contracted cloud AI services delivered through our AWS infrastructure. These are covered under our AWS data processing agreement; no customer PII is used to train public models.
Cloudflare is listed under Cloud Infrastructure above. All processors operate under data processing agreements and are reviewed periodically.
We believe in working with the security community to protect our users. If you believe you have discovered a security vulnerability in our platform, we encourage responsible disclosure.
For security-related enquiries, vulnerability disclosures, or DPO questions, contact us by email or phone. School DPOs: download our data protection pack for DPA, sub-processors, data inventory, and a pre-filled DPIA template.
compliance@iantz.com01509 462745
School DPOs are welcome to request our DPIA summaries and data processing documentation for due diligence purposes.
iAntz is built for UK GDPR and the Data Protection Act 2018. IANTZ LIMITED is ICO registered (ZC093007). Schools can download a data protection pack with a DPA, DPIA template and sub-processor list.
Core application data is hosted primarily on AWS in London (UK). The website and app are delivered via Cloudflare. Some subprocessors may process limited data outside the UK under contractual safeguards — iAntz does not claim UK-only data residency for all personal data.
No. Card payments are processed by Stripe, which is PCI-DSS Level 1 certified. iAntz does not store full card details.
No. Customer personal data is not used to train public AI models. Agentic AI assists with reconciliation, reminders and reporting under human oversight and does not initiate payments or move funds.
Yes. iAntz is Cyber Essentials Plus certified (2026). Independent CREST-accredited penetration testing is also part of the security programme.
Download the pack for your DPO, or talk to our UK team about security and data protection.
School DPOs are welcome to request additional due diligence documentation.