Security and school assurance

Clear controls. Honest pilot boundaries.

BullyShield is designed for sensitive safeguarding work. Schools should be able to understand the controls, responsibilities and current pilot boundaries before any live information is introduced.

Access is limited by school and role

Authorised staff access is separated by school and role. Safeguarding records, actions and evidence are intended to remain available only to people with an approved operational need.

  • School-scoped staff workspaces
  • Role-based permissions for authorised users
  • Privacy-aware audit records of important activity
  • Named ownership and accountable case actions

Safeguarding decisions remain human

BullyShield organises concerns and highlights information that may need attention. It does not replace a Designated Safeguarding Lead, a school's safeguarding policy or professional judgement.

  • Schools control whether anonymous reporting is available
  • Trained staff decide urgency, action and escalation
  • Emergency and independent support routes remain clearly signposted

Agree data handling before the pilot

Before live safeguarding information is used, BullyShield and the school agree the reporting route, authorised users, retention expectations and operational responsibilities. Schools can use this information to support their DPIA and procurement review.

  • Purpose, lawful basis and reporting notices
  • Retention and deletion expectations
  • Evidence handling and access responsibilities
  • Named safeguarding and data-protection contacts

Production assurance is a controlled gate

The founding pilot does not move into live safeguarding use until identity, sensitive storage, monitoring, backup and recovery arrangements have been reviewed for that school. Current demonstrations use pilot data rather than real student reports.

  • Encrypted connections
  • Controlled evidence access
  • Monitoring and incident-response arrangements
  • Backup and recovery review

Procurement information for pilot schools

Pilot applicants can request a concise assurance pack covering the service description, data flow, current subprocessors, access model, retention approach, support route and the responsibilities agreed with the school.

  • Security and architecture summary
  • Data-processing and DPIA information
  • Subprocessor and hosting information
  • Pilot onboarding and success-review plan