Draft for review. Statuses and facts are being verified before publication.
KuraplanTrust Center

Internal working document, not indexed

ST4S questionnaire

Every question from the Supplier Guide 2026.1 (21 June 2026), its answer options, and the answer we intend to give. Question text is machine-extracted from the PDF; check the guide before quoting. Critical means a hash (#) control.

341 questions87 critical192 with a recommended answer
Ready 75Needs build 41Needs document 56Needs decision 17Declare gap 3

Company & product detail

  • C0Tier 1&2

    For which countries are you submitting an ST4S survey Response options: response?

    • A. Australia and New Zealand
    • B. Australia only
    • C. New Zealand only

    Our answerReady

    A

    Australia and New Zealand. We sell in both.

  • C1Tier 1&2

    Vendor name Informational

    No recommendation yet.

  • C2ATier 1&2

    Vendor ABN Informational (AU submissions)

    No recommendation yet.

  • C2BTier 1&2

    Vendor NZBN Informational (NZ submissions)

    No recommendation yet.

  • C3ATier 1&2

    Registered Australian address of vendor Informational (AU submissions)

    No recommendation yet.

  • C3BTier 1&2

    Registered New Zealand address of vendor Informational (NZ submissions)

    No recommendation yet.

  • C4ATier 1&2

    Country in which the company is registered for Australian Informational (AU submissions) customers

    No recommendation yet.

  • C4BTier 1&2

    Country in which the company is registered for New Informational (NZ submissions) Zealand customers

    No recommendation yet.

  • C5ATier 1&2

    For Australian customers: Informational (AU submissions) Preferred vendor contact name Preferred vendor contact email Preferred vendor contact phone number

    No recommendation yet.

  • C5BTier 1&2

    For New Zealand customers: Informational (NZ submissions) Preferred vendor contact name Preferred vendor contact email Preferred vendor contact phone number

    No recommendation yet.

Security

  • P1Tier AllSecurity – Product function

    Name of service

    No recommendation yet.

  • P2ATier AllSecurity – Product function

    Version of service If no published version number, use date of version.

    No recommendation yet.

  • P2BTier AllSecurity – Product function

    Is the service free or paid?

    • A. Free
    • B. Paid

    No recommendation yet.

  • P2CTier AllSecurity – Product function

    For paid services, provide a URL to your pricing page or explain how pricing is determined.

    No recommendation yet.

  • P2DTier AllSecurity – Product function

    Are you the product or service’s original developer, a re- seller or ‘other’?

    • A. Original developer
    • B. Reseller
    • C. Other (please specify)

    No recommendation yet.

  • P2ETier AllSecurity – Product function

    Do you warrant that you have the legal authority to submit this product or service for an ST4S assessment?

    • A. No#
    • B. Yes (T1, T2)

    No recommendation yet.

  • P2FTier AllSecurity – Product function

    Does your organisation outsource any development, maintenance or operation activities to another organisation?

    • A. No
    • B. Yes (please specify)

    No recommendation yet.

  • P3ATier AllSecurity – Product function

    URLs for Australian customers

    No recommendation yet.

  • P3BTier AllSecurity – Product function

    URLs for New Zealand customers

    No recommendation yet.

  • P4ATier AllSecurity – Product function

    URL of Terms of Service/use for Australian customers

    No recommendation yet.

  • P4BTier AllSecurity – Product function

    URL of Terms of Service/use for New Zealand customers

    No recommendation yet.

  • P5Tier AllSecurity – Product function

    Purpose of the service?

    No recommendation yet.

  • P6Tier 1&2Security – Product function

    In what jurisdiction would disputes, regarding usage of the service, be handled? (e.g., Victoria Australia, New Zealand)

    No recommendation yet.

  • P7Tier 1Security – Product function

    Does your organisation have a current insurance policy of at least $1M AUD with claims for data breach/loss?

    • A. Yes - current policy with coverage of at least $1 million AUD (T1)
    • B. Yes - current policy but coverage is less than $1 million AUD
    • C. No current policy

    No recommendation yet.

  • P8Tier AllSecurity – Product function

    Are there any additional setup steps or requirements that your service needs to function for its intended purpose, including: • Requiring users to register or access another service in addition to yours (e.g. users must also be able to access YouTube for video content); • Unblocking additional domain names or IP addresses; • Adjusting DNS settings (e.g. adding a CNAME record etc); • Installing or deploying middleware (e.g. hybrid hosted setups); • Requiring specific hardware such as Internet of Things (IoT) devices, wearable devices etc; • Firewall or network changes

    • A. Yes, please specify
    • B. No

    No recommendation yet.

  • P9Tier AllSecurity – Product function

    When using the service for its intended purpose, what, if •Protection order details (student) NZ PSR – INFOSEC1 any, of the data types below would reasonably be •Legal custodial arrangements (student) captured, stored, or processed by the service? Select all •Informal custodial arrangements that apply. •Legal status (criminal convictions, protection orders, police checks results etc) Sensitive information is a type of personal information that •Out of home care status (student) is given extra protection and must be treated with •Records of behaviour incidents (student) additional care. If in doubt, select this option. Sensitive •Records of incidents information may include: •Behavioural observations/notes (student) - Protection details (i.e., whether the user is under a •Records of contact or interview (student) protection order and/or the details of the order) •Sensitive social, emotional or mental health - Legal custodian arrangements and court orders and well-being information (staff, student, - Out of home care status parent) - Records of behaviour incidents/discipline, behavioural •Support arrangements (student) observations/notes •Professional case notes (student) - Consent (e.g., collection and/or recording of consent) •Reason for absence (student) - Student absence details (i.e., records of attendance and •Commonwealth Unique Student Identifier (AU) reason for absence) or National Student Number (NZ) - Records of contact (e.g., between parents, teacher, school, •Health and medical details, including mental and/or student) and other agencies health diagnoses (staff, student, parent) - Student/Learning support service information and support •Personal health or fitness information (e.g. arrangements step counts, heart rate, calories burned, sleep - Enrolment support records (sensitive case, complex case, duration / patterns, other fitness or physical adjustments, student plan, developmental map, activity metrics) (student, staff, parent) transportation, Individual Education Plans, Oranga •Wellbeing information (e.g. mood check-ins, Tamariki ‘All about Me’ plan) self-reflections, wellbeing journals etc) (student, staff, parent) •Financial information (staff, student, parent, organisation) •Identification documentation (staff, student, parent) •Digital signature (staff, student, parent) •Government related Identifiers (e.g., state or federal government assigned identifiers) •Official records •Racial or ethnic origin •Religious beliefs or affiliations •Sexual orientation or practices •Biometric information (e.g., eye/retinal/facial imagery, fingerprints, biometric templates) •Location tracking data (Information about the ongoing geographic positions of individuals or devices derived from GPS or other network sources. Examples include: Current position in time and retained point in time, ongoing positions of individuals, cellular network connection tracking, BLE (Bluetooth Light Energy) beacons communication) • Use of social services (Work & Income, ACC, CYPS, Women’s refuge etc) • None of the above (T2)

    Our answerNeeds build

    None of the above

    No fields for health, disability, ethnicity, religion, government IDs or finances. Must remain true: remove the learner 'notes' free-text field first.

  • P10Tier AllSecurity – Product function

    Select the functionality available within the service. Select • Online meetings, video or audio conferencing, all that apply. livestreaming (T1) • Consent Management (T1) • Financial management or payment processing systems (T1) • Enrolment management (T1) • Student information, student management system, school administration or student administration system (T1) • Customer relationship management (T1) • Ticketing system - Service Management, Helpdesk (T1) • Learning management system (T1) • Electronic document and records management systems (T1) • File hosting and synchronisation (T1) • Remote access (T1) • Data collection tools (non-curriculum) (T1) • Photo, image, video or audio storage, sharing and backup services (T1) • Two-way communication tools (T1) • Data aggregation, Data broker, Data hub, Data distribution hub (T1) • Data aggregation, analytics, insights and reporting (T1) • Software and cloud developer tools (T1) • Mobile device management (MDM) (T1) • Authentication services (T1) • Collaboration and sharing (T2) • One-way communication tools (T2) • Career education, planning and guidance (T2) • Vocational training providers and courses, industry/employment registers, work placements (T2) • Learning activities, assessments and games (T2) • Content creation, presentation tools and publishing (T2) • Educational resources and content libraries (T2) • File download, including executables (T2) • Library Management (T2) • Visitor Management (T2) • Event management, bookings, online ordering or fundraising (T2) • Administrative support services and tools (T2) • None of the above (T2)

    Our answerReady

    Content creation; educational resources and content libraries; learning activities

    Declare Activities (student responses stored) honestly. Do not select LMS or student information system.

  • P11Tier AllSecurity – Product function

    Does the service promote or display any of the following (e.g. via social media, ads, pop-ups): • Restricted products: alcohol, banned substances, gambling, tobacco, firearms, adult content. • Offensive content: e.g. racist, sexist, or pornographic material.

    • A. Yes (please specify)
    • B. No (T1,T2)

    Our answerNeeds decision

    No advertising; content filtered

    Own-plan upsells are allowed. Third-party ad scripts must be out of the app first (decision pending).

  • P12Tier 1Security – Product function

    With respect to any third-party providers that compose your solution or deliver services to your organization, does your organisation perform all of the following: • Maintain an up-to-date inventory of all third-party service providers • Regularly assess and manage the risks associated with these providers • Have contractual agreements in place to ensure that third-party providers comply with your information security and privacy policies?

    • A. No
    • NZ PSR - GOV5
    • B. Yes - for some third-party providers NZISM 12.7
    • C. Yes - for all third party-providers (T1) NZPP-5 NZPP-11
    • D. NA - solution does not use third party providers (T1)

    No recommendation yet.

  • P13Tier AllSecurity – Product function

    How is the service deployed for customers?

    • A. Customer-hosted (self-managed environment)
    • B. Supplier-hosted (e.g. cloud or managed service by your organisation)
    • C. Hybrid – part hosted by customer, part by your organisation

    No recommendation yet.

  • P14Tier AllSecurity – Product function

    Does the service meet the Web Content Accessibility Guidelines (WCAG) to ensure that digital content is accessible to people with disabilities? Specify the WCAG version and level

    • A. Not WCAG compliant
    • NZ Govt Web Standards
    • B. Yes – all components meet WCAG 2.0
    • C. Yes – all components meet minimum of WCAG 2.1
    • D. Yes – all components meet minimum WCAG 2.2

    No recommendation yet.

  • P15Security – Product function

    Retired (2025)

    No recommendation yet.

  • H0Security – Hosting and Location

    Select from the following cloud service providers which are used by your service:

    • A. Amazon Web Services (AWS)
    • B. Google Cloud (GCP)
    • C. Microsoft Azure
    • D. Digital Ocean
    • E. Other cloud service provider (please specify)
    • F. Other infrastructure provider (please specify)
    • G. N/A - No third party infrastructure or cloud service providers used

    No recommendation yet.

  • H1Tier 1&2Security – Hosting and Location

    Select the option which best describes where user data or any related data (e.g., metadata, logs, user content) is stored or processed across all components of the service, including live solution, backup, disaster recovery, test environment, and development environments. (specify country) C. In multiple vendor nominated countries: specify country/s)

    • A. Entirely in a country nominated by the customer (specify supported countries for Australian and New Zealand customers) (T1, T2)
    • B. Entirely in a single vendor nominated country NZPP-11 - Live solution (please specify country/s) - Other components (backup, etc) (please

    Our answerNeeds decision

    United States for every component; Germany for product analytics (PostHog)

    Say each country exactly. Sydney migration would change this; decide before submitting.

  • H2Tier 1&2Security – Hosting and Location

    From what countries do vendor staff, including support, administration, development and testing, and external contractors or associates, access or view user data and any related data (e.g., metadata, logs) collected or used by the service (including backups and recovery)?

    • A. Entirely from Australia and / or New Zealand (please specify)
    • B. From other countries (please specify country/s)

    Our answerReady

    United Kingdom

    Founder works remotely from the UK via MFA-protected consoles.

  • H3Security – Hosting and Location

    Retired (2022)

    No recommendation yet.

  • H4Tier 1Security – Hosting and Location

    At a minimum, which of the following physical access controls are in place at data storage locations? Select all that apply.

    • A. No public access
    • B. Only visitors with need to know permitted and have a close escort at all times
    • C. Restrict access to authorised personnel with appropriate security clearance
    • D. Access control using secure swipe card, biometrics, coded access, or similar
    • E. Monitored security alarm system

    No recommendation yet.

  • H5CriticalTier 1&2Security – Hosting and Location

    Would customers be notified in advance if the cloud infrastructure, data‑hosting environment, organisational staff, or any personnel with access to unencrypted customer data were to be relocated or expanded into another country?

    • A. No (#T1, #T2)
    • B. Yes (specify average notification lead time) (T1, T2)

    Our answerNeeds document

    B, 30 days

    Add the clause to terms and the school agreement, then answer B.

  • H6Tier 1&2Security – Hosting and Location

    Are all infrastructure providers, cloud-based services and other service components assessed under either of the following: • IRAP • SOC2 Type 2 • ISO27001 See https://www.cyber.gov.au/irap for information about IRAP assessment.

    • A. No or unknown
    • B. Yes – some hosting providers, cloud-based services and other components are IRAP, ISO27001, or SOC2 Type 2 assessed
    • C. Yes – all cloud-based services and other components are IRAP, ISO 27001 or SOC2 Type 2 assessed (T1, T2)

    Our answerReady

    Some

    AWS (under Supabase and Vercel) is IRAP-assessed; Supabase and Vercel themselves are not.

  • S1CriticalTier 1&2Security – Technical

    What are the minimum encryption algorithms applied to protect all data in transit over networks, including encryption of data that is communicated between the user, web applications and system components (e.g., database systems)?

    • A. No encryption (#T1, #T2)
    • B. Weak Encryption: DES, RC4, 3DES using three distinct keys; Hashing: Message Digest (MD to MD6), RIPEMD-128 or above, SHA-0, SHA-1; Digital Signatures: RSA (2048); Key Exchange: DH (1024) or RSA (2048); Protocol: TLS1.1 or below
    • C. Standard Encryption: AES 128 or above; Hashing: SHA-224 or above; Digital Signatures: FIPS 186-5, ECDSA (224+) preferably using NIST P-384 curve or RSA (2048+); Key Exchange: DH (2048+), ECDH (256+) preferably using NIST P-384 curve or RSA (2048+); Protocol: TLS1.2. (T2)
    • D. Strong Encryption: AES 192 GCM/CCM, CHACHA20 POLY1305 or above only (AES 256 GCM/CCM recommended) Hashing: SHA-256 or above only (SHA-384 recommended) Digital Signatures: FIPS 186-5 ECDSA (224+) using NIST P-384 curve or RSA (2048+); Key Exchange: DH (3072+), ECDH (256+) using NIST P- 384 curve or RSA (3072+) Protocol: TLS 1.3 (TLS 1.2 for compatibility). (T1, T2)

    Our answerReady

    D

    Hosts negotiate TLS 1.3 with AEAD ciphers today (verified 15 Sep). Confirm Vercel's cipher list excludes non-AEAD TLS 1.2 suites, or answer C and explain.

  • S2CriticalTier 1&2Security – Technical

    What are the minimum encryption algorithms applied to protect data at rest, including backups, data storage, removable media and auditable logs?

    • A. No encryption (#T1, #T2)
    • B. DES, RC4, 3DES using three distinct keys
    • C. AES 128 (T2)
    • D. AES 192, AES 256 (AES 256 recommended) (T1)
    • E. Encryption algorithm equivalent to options C or D (please specify equivalent algorithms)

    Our answerReady

    D

    Supabase on AWS encrypts at rest with AES-256. Attach Supabase's security page.

  • S3CriticalTier 1&2Security – Technical

    If customer data is uploaded to the service using a mechanism such as encrypted USB, SFTP, Secure API, etc., what are the minimum encryption methodologies applied?

    • A. No encryption (#T1, #T2)
    • B. Weak Encryption: DES, RC4, 3DES using three distinct keys; Hashing: Message Digest (MD to MD6), RIPEMD-128 or above, SHA-0, SHA-1; Digital Signatures: RSA (2048); Key Exchange: DH (1024) or RSA (2048); Protocol: TLS1.1 or below
    • C. Standard Encryption: AES 128 or above; Hashing: SHA-224 or above; Digital Signatures: FIPS 186-5, ECDSA (224+) preferably using NIST P-384 curve or RSA (2048+); Key Exchange: DH (2048+), ECDH (256+) preferably using NIST P-384 curve or RSA (2048+); Protocol: TLS1.2. (T2)
    • D. Strong Encryption: AES 192 GCM/CCM, CHACHA20 POLY1305 or above only (AES 256 GCM/CCM recommended) Hashing: SHA-256 or above only (SHA-384 recommended) Digital Signatures: FIPS 186-5 ECDSA (224+) using NIST P-384 curve or RSA (2048+); Key Exchange: DH (3072+), ECDH (256+) using NIST P- 384 curve or RSA (3072+) Protocol: TLS 1.3 (TLS 1.2 for compatibility). (T1, T2)
    • E. N/A - Customer data is not uploaded to the service

    Our answerReady

    D

    Uploads only over HTTPS to the same hosts as S1.

  • S4CriticalTier 1&2Security – Technical

    If the system uses multi-tenancy architecture (where system components are shared across multiple customers), which of the following controls are implemented to ensure secure segregation of each customer’s data? Select all that apply:

    • A. Unique customer identifiers when a shared table stores data for multiple customers
    • B. Separate tables or databases for each customer
    • C. Dedicated instances, environments, or VPCs
    • D. All of the above
    • E. None of the above (#T1, #T2)
    • F. Not applicable, multi-tenancy is not used

    Our answerReady

    A

    Shared tables with per-user and per-school row-level security. Attach the RLS inventory.

  • S5CriticalTier 1&2Security – Technical

    Are all of the service’s web servers secured with digital certificates signed by a reputable trusted authority?

    • A. Yes (please specify CA) (T1, T2)
    • B. No (#T1, #T2)

    Our answerReady

    A, Let's Encrypt

    Verified on every host 15 Sep.

  • S6Tier 1Security – Technical

    Does your organisation have a documented and implemented certificate and key management process which describes at a minimum: • Key generation; • Key registration; • Key storage; • Key distribution and installation; • Key use; • Key rotation; • Key backup; • Key recovery; • Key revocation; • Key suspension; and • Key destruction?

    • A. No - none of the above
    • B. Yes - some of the above
    • C. Yes - all of the above (T1)

    No recommendation yet.

  • S7CriticalTier 1&2Security – Technical

    Which of the following protections are in place for your production environments (production servers, containers, serverless services and endpoints)? Select all that apply.

    • A. Intrusion detection systems (IDS), Host-based intrusion detection (HIPS)
    • B. Software-based application or web application firewall (WAF) (T2)
    • C. Anti-virus and malware detection
    • D. All of the above (T1)
    • E. None of the above (#T1, #T2)

    Our answerNeeds build

    D with explanation

    WAF: Vercel Firewall. IDS: platform-level detection by Vercel and AWS (no hosts of our own). AV: needs upload malware scanning built. Until then answer B+C honestly and give a date.

  • S8CriticalTier 1&2Security – Technical

    Does your organisation enforce the following controls on database management system (DBMS) software: • Follow vendor guidance for securing the database; • DBMS software features and stored procedures, accounts and databases that are not required are disabled or removed; • Least privileges; • File-based access controls; • Disable anonymous and default database administrator account; • Unique username and password for each database administrator account; • Use database administrator accounts for administrative tasks only; and • Segregate production from any non- production environments?

    • A. No - none of the above (#T1, #T2)
    • B. Yes - some of the above
    • C. Yes - all of the above (T1, T2)

    Our answerNeeds build

    C

    Vendor guidance, least privilege, no default admin, browser roles denied by default (15 Sep), prod separated from dev (dev project created 15 Sep). Needs the remaining security-definer cleanup finished.

  • S9CriticalTier 1&2Security – Technical

    Are internet facing components (e.g., web servers) separated from other online components (e.g. databases) using the following controls: • Secure communication between network segments (e.g., using firewalls), including filtering between network segments • DMZ for internet-facing components and separate trusted zones for other components • Virtual (e.g., VLAN) or physical network segregation

    • A. No – none of the above (#T1)
    • B. Partial – secure communication or DMZ
    • C. Partial – virtual or physical network segregation (T2)
    • D. Yes – all of the above (T1, T2)

    Our answerNeeds build

    D once SSL enforcement is on

    Database sits behind Supabase's pooler; SSL enforcement must be enabled in a scheduled window (attempt on 15 Sep caused a restart). Until then answer C.

  • S10CriticalTier 1&2Security – Technical

    Does your organisation maintain a documented and implemented system hardening standard, that applies to all infrastructure and endpoint components (e.g., OS, hypervisors, storage, network, applications, and user devices), that: • incorporates vendor and industry best practice, • enforces the removal of default credentials and unnecessary services, • restricts non-essential ports/protocols • includes regular audit of configurations • and is reviewed at least annually or upon significant change?

    • A. No – none of the above (#T1, #T2)
    • B. Yes – some of the above
    • C. Yes – all of the above except annual review (T2)
    • D. Yes – all of the above (T1)

    Our answerNeeds document

    D

    Write the hardening standard (one page) and date the first annual review.

  • S11CriticalTier 1&2Security – Technical

    Has your organisation implemented the following perimeter controls: • External Firewall; • IDS/IPS (Intrusion Detection System/Intrusion Prevention System); • DMZ (Demilitarised Zone) for hosting external sites; • Content filtering (including blocking of unnecessary file types); • DoS/DDoS (Denial of Service/Distributed Denial of Service) defence; • Web Application Firewall (WAF); • Filtering and monitoring of outgoing traffic (spikes, unusual activity, malicious content); • Network segmentation; • VPN required for remote access; • Detection and monitoring of unauthorised devices on the network; • DNS filtering and network URL based filters; and • Organisation assets are configured to use trusted DNS servers?

    • A. No - none of the above (#T1, #T2)
    • B. Yes - some of the above
    • C. Yes - all of the above except for Web Application Firewall (WAF) (T2)
    • D. Yes - all of the above (T1)

    Our answerReady

    D, with the serverless mapping stated per bullet

    Verified 15 Sep 2026 from the live Vercel Firewall config (evidence 01-infrastructure/2026-09-15-vercel-firewall-config.md). External firewall + DoS/DDoS defence + WAF: Vercel Firewall on the API, app and website, managed rulesets for generic attacks, RCE, XSS and SQL injection, per-IP rate limits, bot challenges on the website. IDS/IPS: no hosts of our own; platform-level detection by Vercel and AWS (Supabase), plus Sentry and usage alerts. DMZ: not applicable, there are no self-hosted servers; every public surface is a serverless function behind the edge. Content filtering: uploads restricted to images (re-encoded) and PDF/text/Office documents up to 25 MB; malware scanning planned. DNS: Namecheap with DNSSEC enabled 16 Sep 2026 (DS published, resolvers validating). State each mapping in the free text rather than claiming hardware we do not run.

  • S12Security – Technical

    Has your organisation documented and implemented 1 & 2 a security policy for managing mobile devices, including the use of a Mobile Device Management (MDM) solution on all mobile devices? Please select the option that best reflects your current practices:

    • A. No – Neither a policy nor MDM has been implemented. (T2)
    • B. Partially – A policy is in place, but MDM is not applied to all devices. (T2)
    • C. Yes – A policy is in place and MDM is applied to all mobile devices. (T1)

    No recommendation yet.

  • S13CriticalTier 1&2Security – Technical

    Is production data used in non-production (e.g., test and development) environments?

    • A. Yes – without identical security controls applied and de-identification of production data. (#T1, #T2)
    • B. Yes - with identical security controls applied and/or with production data de-identified (T1, T2)
    • C. No (T1, T2)

    Our answerNeeds build

    C

    True once local dev and previews point at the dev project with synthetic data. Delete any prod dumps.

  • S14Tier 1&2Security – Technical

    Does your organisation: • disable the internal use of business productivity tool macros (e.g., Microsoft Office macros) and scripts (VB, java, PowerShell) for users that don’t have a demonstrated business requirement; • block macros in files originating from the internet; • enable macro antivirus scanning; and • ensure macro security settings can’t be changed by users?

    • A. No
    • B. Yes – some of the above
    • C. Yes – all of the above (T1, T2)
    • D. N/A (T1, T2)

    Our answerReady

    N/A

    No office productivity macros in use.

  • L1Tier 1&2Security – Logging

    Does your organisation enforce a documented logging policy requiring all systems (e.g., servers, storage, network, applications) to capture: • successful and unsuccessful authentication attempts including multi-factor, • privileged activity, • user administration, • and system events, • information about each event per the ISM-1683 logging requirements, • with logs synchronised to a unified time source and protected against unauthorised access or tampering? ISM-1683 logging requirement: • the date and time of the event, • the relevant user or process, • the relevant filename, • the event description, • and the information technology equipment involved are captured.

    • A. No - none of the above
    • B. Yes - some of the above (T2)
    • C. Yes - all of the above (T1)

    No recommendation yet.

  • L2Tier 1&2Security – Logging

    Does your organisation have a documented and implemented event log auditing procedure which outlines, at a minimum: • Schedule of audits (annual or real-time for sensitive data); • Definitions of security violations; • Actions to be taken when violations are detected; and • Reporting requirements?

    • A. No
    • B. Yes - all of the above without real-time monitoring (T2)
    • C. Yes - all of the above with real-time monitoring (T1)

    No recommendation yet.

  • L3Tier 1&2Security – Logging

    Will you supply all relevant audit and logging data in response to customer requests?

    • A. No
    • B. Yes (T1, T2)

    No recommendation yet.

  • L4Tier 1Security – Logging

    Has your organisation implemented a centralised logging facility to store logs?

    • A. No
    • B. Yes (T1)

    No recommendation yet.

  • A0Tier 1&2Security – Access

    What authentication methods are available for end users, select all that apply:

    • A. Username/email address and password
    • B. Passkeys / WebAuthn (e.g. FIDO2- compliant hardware or platform authenticators)
    • C. Magic link (one-time login link sent via email)
    • D. One-time password (OTP) via SMS or email
    • E. Time-based one-time password (TOTP) apps (e.g. Google Authenticator)
    • F. Hardware token (e.g. YubiKey, RSA SecurID)
    • G. Single Sign-On (SSO) via SAML, OAuth2 / OIDC, etc.
    • H. Biometrics (please specify)
    • I. Other (please specify)

    No recommendation yet.

  • A1CriticalTier 1&2Security – Access

    Are all users of the service (e.g. Teachers, Parents, Students, Admins etc) required to be uniquely authenticated and identifiable within the service (e.g. B. Yes for all users – excluding students each user is assigned a username and login credential)? C. Yes for all users (T1, T2)

    • A. No (Please detail why this exception is required and specify any controls in place for students) (T1, T2)

    Our answerReady

    B

    Every teacher and parent has a unique account. Students complete activities via a teacher link without accounts; explain why and what controls apply.

  • A2CriticalTier 1&2Security – Access

    Are all passwords used to access the service protected in line with the following: • Passwords are hashed using a strong, salted, one- way algorithm (e.g., Argon2id, bcrypt, scrypt, PBKDF2) following OWASP recommendations; • Support for long passphrases (≥64 characters), Unicode characters, and a minimum length aligned with relevant standards (e.g., ≥14 under ISM or shorter with MFA); • New passwords are checked against lists of weak, common, or breached passwords; • Authentication attempts are throttled (e.g., rate- limiting/backoff).

    • A. No (#T1, #T2)
    • B. Yes - for all user accounts, with exceptions for student accounts (please describe).
    • C. Yes for all users (T1, T2)

    Our answerReady

    C with explanation

    No passwords exist. Sign-in is Google or a single-use emailed code (1 hour expiry, rate-limited). Describe the code path against each bullet.

  • A3Tier 1&2Security – Access

    Do all supplier staff, external contractors, or associates with access to the organisation’s systems and the service meet the following minimum password requirements? • Single-factor authentication: Minimum 15- character password with complexity controls to prevent predictability • Multi-factor authentication (MFA): Minimum 8- character password

    • A. No
    • B. Yes (T1, T2)

    No recommendation yet.

  • A4CriticalTier 1Security – Access

    Within the service, do you offer multi-factor authentication for end-users including school staff, parents and students?

    • A. No (#T1)
    • B. Yes, MFA is offered for all account types (T2)
    • C. Yes, MFA is mandated for all non-student accounts (T1)
    • D. Yes, MFA is mandated for all account types (T1)

    Our answerNeeds build

    B. MFA offered for all account types; schools can require it for their teachers

    Two-step sign-in (authenticator app) built 16 Sep 2026 with a per-school require switch and server-side enforcement (PR #785, reviewed). Answer B once released; C needs it mandated for every non-student account.

  • A5CriticalTier 1&2Security – Access

    Does your organisation mandate two factor authentication for: • Vendor staff, external contractors or associates accessing systems remotely; • System administrators; • Support staff; and • Staff with privileged accounts?

    • A. No – none of the above (#T1)
    • B. Yes – some of the above (please specify which accounts)
    • C. Yes – all of the above (T1, T2)

    Our answerReady

    C

    Only the founder has admin access; MFA on every console. Screenshot each console.

  • A6CriticalTier 1&2Security – Access

    Does your organisation implement documented role‑based access control (RBAC) for all systems, requiring formal approval of roles, identification of systems and roles that must follow least‑privilege principles, and prohibit the use of privileged accounts for non‑administrative activities?

    • A. No (#T1)
    • B. Yes, for some systems
    • C. Yes, for all systems (T1, T2)

    Our answerNeeds document

    C

    Write the RBAC register: product roles (teacher, school admin, Kuraplan admin) and every console.

  • A7CriticalTier 1&2Security – Access

    At a minimum, are vendor staff, external contractors or associates with access to systems, applications and information (including audit logs): • Validated and approved by appropriate personnel; • Periodically reviewed (at least annually) and revalidated or revoked; and • Reviewed and revalidated or revoked following changes to role, employment and/or inactivity?

    • A. No (#T1)
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Access register with a dated first review.

  • A8Tier 1&2Security – Access

    Do supplier personnel (including contractors) have remote or terminal access to customer/school ICT infrastructure such as devices, servers, networks, or systems?

    • A. Yes (please specify)
    • B. No (T1, T2)

    Our answerReady

    B

    No remote access to customer devices or networks.

  • A9Tier 1&2Security – Access

    Are vendor staff, external contractors or associates with non-privileged accounts restricted from installing, uninstalling, disabling or making any changes to software and system configuration on servers and endpoints, and are dedicated privileged accounts used for duties requiring privileged access?

    • A. No
    • B. Yes, non-privileged accounts are restricted
    • C. Yes, non-privileged accounts are restricted and dedicated privileged accounts are used (T1,T2)

    Our answerNeeds document

    C

    Founder uses a dedicated admin identity for consoles; document it.

  • A10CriticalTier 1&2Security – Access

    Are all internal organisation systems configured with a session or screen lock that: • activates after a maximum of 15 minutes of user inactivity or if manually activated by the user; • completely conceals all information on the screen; • ensures that the screen does not enter a power saving state before the screen or session lock is activated; • requires the user to reauthenticate to unlock the system; and • denies users the ability to disable the session or screen locking mechanism?

    • A. No (#T1)
    • B. Yes, some of the above
    • C. Yes, all of the above (T1, T2)

    Our answerReady

    C

    macOS lock verified 15 Sep; screenshot the 'require password' setting.

  • A11CriticalTier 1&2Security – Access

    Does the service’s password reset/recovery process meet the following security requirements: • issues a single-use and time-limited reset link / token • delivers tokens only via verified, trusted channels (e.g. registered email or SMS with safeguards); • requires the user to create a new password immediately after token validation and invalidates the token after use/expiry; • implements rate-limiting and monitoring of reset requests and prevents account enumeration (no disclosure of whether an account exists); and • invalidates active sessions/refresh tokens upon a successful password reset.

    • A. No (#T1)
    • B. Yes, some of the above
    • C. Yes, all of the above (T1, T2)

    Our answerReady

    C with explanation

    No password reset exists. Sign-in codes are single-use, time-limited, delivered by email; sessions revoked on sign-out. Answer C describing this.

  • A12Tier 1&2Security – Access

    In relation to Single Sign-On (SSO) please specify all standards or providers supported:

    • A. OAUTH 2.0
    • B. OIDC
    • C. SAML 2.0
    • D. Microsoft Entra
    • E. Google Classroom / Workspace
    • F. Other (please specify)

    Our answerReady

    Google OAuth; Microsoft planned

    Informational.

  • A13CriticalTier 1&2Security – Access

    What is the service’s approach to default user access permissions (e.g., all access is denied unless specifically allowed, all access is allowed unless specifically denied)?

    • A. Protection by exception (Allow access unless specifically denied) (#T1, #T2)
    • B. Protection by default (Deny unless approved) (T1, T2)

    Our answerReady

    B

    Deny by default across the database, verified 15 Sep.

  • A14Security – Access

    Retired 2025

    No recommendation yet.

  • A15Tier 1&2Security – Access

    If customers can or are required to supply data to the Select all that apply: service, what methods or mechanisms are available to support this?

    • A. Flat file upload (e.g. CSV, XLS)
    • B. API
    • C. Creating or using a user/admin account in a third party service to directly access the data
    • D. Direct access to the customer's database (e.g. SQL user, database agent software)
    • E. Third party data integration platform (please specify)
    • F. Other (please specify)
    • G. Not applicable

    Our answerReady

    Manual entry; Google sign-in profile

    No CSV import of student data today.

  • A15ATier AllSecurity – Access

    Please provide further information on all methods available to supply data to the service, including any references or support articles if available.

    No recommendation yet.

  • A16ATier 1&2Security – Access

    Does your organisation or service request a school share access credentials or create a user account in another system or service (e.g. creating a user account in another service to facilitate data extraction)?

    • A. Yes (Please specify)
    • B. No (T1, T2)

    Our answerReady

    B

    We never ask a school to create accounts for us elsewhere.

  • A16BTier 1&2Security – Access

    In relation to the creation of accounts in third party # services, are enforceable written agreements in place Conditi with all of these third-party services covering this onal arrangement? (A15 – yes)

    • A. No (#T1, #T2)
    • B. Yes (T1, T2)

    No recommendation yet.

  • A16CTier 1&2Security – Access

    Who creates the account/s in the third-party service? Conditi onal (A15 – yes)

    • A. The school, school system or jurisdiction
    • B. The third-party service
    • C. The service (responding to this assessment)

    No recommendation yet.

  • A17Tier 1&2Security – Access

    Within the vendor organisation, is application control: • Implemented on all workstations; • Implemented on internet-facing and non-internet facing servers; • Enabled to restrict the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set; • Enabled to restrict the execution of drivers to an organisation-approved set; • Implemented using cryptographic hash rules, publisher certificate rules or path rules; • Rulesets are validated on an annual or more frequent basis; and • When implementing application control using publisher certificate rules, both publisher names and product names are used.

    • A. No, none of the above
    • B. Yes, some of the above
    • C. Yes, all of the above (T1, T2)

    Our answerReady

    Gatekeeper enforced; serverless has no persistent servers

    Screenshot Gatekeeper.

  • A18Tier 1&2Security – Access

    Does your service offer alternative access methods such as reduced password requirements for younger students, temporary session join codes for classroom activities or similar?

    • A. No
    • B. Yes (please specify including any reasoning for review)

    No recommendation yet.

  • A19Tier 1&2Security – Access

    What options are available for an administrator to configure and apply secure authentication policies for their school / user base?

    • A. Administrator can set a minimum password length and complexity rule for users
    • B. Administrator can enforce MFA for users
    • C. Other (please specify)

    No recommendation yet.

  • HR1CriticalTier 1Security – HR

    Do all vendor staff, external contractors and associates who have access to user data or user content undergo employment screening (e.g., criminal history checks, working with children checks) as per applicable regulatory requirements?

    • A. No (#T1)
    • B. Yes (T1, T2)

    Our answerDeclare gap

    B after the DBS/police check

    Apply now; takes weeks. Answer A honestly until it arrives.

  • HR2CriticalTier 1&2Security – HR

    Does your organisation run a security, privacy and online safety awareness/education program for your staff which addresses the following at a minimum: • Identification of who the awareness training needs to be delivered to; • Identification of when awareness training needs to be delivered (e.g., during induction, annually, etc.); • Identification of how the awareness training is to be delivered (e.g., classroom training, online course, security awareness posters, emails, etc.); • Recording all training in a training register; • Reporting, regular review and updates as part of the organisation's training progrmme; • Delivery of the following training content to all personnel including as part of onboarding: o Basic understanding of the need for information security, privacy and online safety; o Awareness of the causes of unintentional data exposure and the dangers of connecting to insecure networks; o Actions to maintain security, privacy and online safety; o How to recognise and respond to suspected security, privacy and online safety incidents; o Applicable policies and laws; • Annual tailored training for privileged users • Practical security, privacy and online safety awareness exercises, and o Disciplinary actions for significant security and privacy breaches by staff?

    • A. No - none of the above (#T1)
    • AU ISM Security Control: 0252
    • B. Yes - some of the above AU ISM Security Control: 1565
    • C. Yes - all of the above (T1, T2) NZISM 9.1 NZISM 3.2.18 NZISM 3.3.13 NZISM 7.1.7 MCSS Security awareness level 2

    Our answerNeeds document

    C

    Complete one recognised course, keep a training register, write the one-page programme.

  • HR3CriticalTier 1&2Security – HR

    Is there a documented and implemented process to remove access to systems, applications and data repositories for personnel (vendor staff, external contractors and associates) that: • no longer have a legitimate requirement for access (implemented on the same day); and • are detected undertaking malicious activities (implemented immediately)?

    • A. No (#T1, #T2)
    • B. Yes – but not implemented within required timeframes
    • C. Yes – (T1, T2)

    Our answerNeeds document

    C

    Offboarding checklist listing every system, same-day removal.

  • HR4Security – HR

    Does the service enable vendor personnel (including employees, contractors, or volunteers) to interact directly with students in any form? This includes, but is not limited to, 1:1 or group instruction, tutoring, mentoring, messaging or chat functions, discussion forums, email, screen sharing, video or audio communication, or any other form of direct or indirect communication.

    • A. No – The service does not enable any direct interaction between vendor personnel and students
    • B. Yes – The service enables direct interaction between vendor personnel and students

    Our answerReady

    A

    No channel exists for Kuraplan staff to interact with students.

  • HR4ASecurity – HR

    Where direct interaction with students occurs, does the organisation ensure that all personnel comply with applicable child safety, screening, and engagement requirements in relevant jurisdictions?

    • A. Yes – All personnel meet jurisdictional requirements (e.g. Working with Children Check), with verification and ongoing monitoring in place
    • B. Partially - Some controls are in place, but not all requirements are consistently met or monitored
    • C. No - Personnel are not required to meet jurisdictional child safety or screening requirements

    No recommendation yet.

  • T1CriticalTier 1&2Security – Processes and Testing

    Does your organisation have an implemented continuous monitoring plan for all organisational systems and infrastructure that includes: • conducting automated discovery of assets • conducting regular automated vulnerability scans to identify missing patches or updates for vulnerabilities using an up to date vulnerability database • conducting penetration tests for systems after a major change or at least annually • analysing identified security vulnerabilities to determine their potential impact and appropriate mitigations based on effectiveness, cost and existing security controls • using a risk-based approach to prioritise the implementation of identified mitigations.

    • A. No (#T1, #T2)
    • B. Yes - meets all requirements above (T1, T2)
    • C. Yes – meets all requirements above including the use of external independent resources to conduct penetration testing (T1, T2)

    Our answerDeclare gap

    C once the pen test is done; B meanwhile

    Dependabot alerts on (15 Sep). Book the external pen test.

  • T2CriticalTier 1&2Security – Processes and Testing

    Does your organisation use a centrally managed approach to patch or update applications, drivers, operating systems, software defined infrastructure and firmware which includes ensuring: • the integrity and authenticity of patches; • approval of patches as part of change management processes; • successful application of patches; • rollback procedures are in place if a patch deployment is unsuccessful • that patches remain in place, and • that services, software and operating systems are retired, upgraded or replaced at least 6 months before their end-of-support date?

    • A. No
    • B. Yes – centrally managed patching with retirement before end-of-support
    • C. Yes – all of the above (T1, T2)

    Our answerNeeds document

    C

    Lockfiles + Dependabot PRs + CI. Write the patch process incl. rollback and end-of-support rule.

  • T3CriticalTier 1Security – Processes and Testing

    Are patches, updates or vendor mitigations for security vulnerabilities in: • internet facing services (including operating systems of internet-facing services); • workstation, server and network device operating systems; • operating systems of other ICT equipment; and • drivers and firmware; applied within two weeks of release, or within 48 hours if an exploit exists?

    • A. No (#T1)
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Commit to 2 weeks / 48 hours for critical. Keep a log of advisories and fix dates.

  • T4Tier 1&2Security – Processes and Testing

    Are patches, updates, or vendor‑provided mitigations for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products applied within two weeks of the manufacturer making them available, or within 48 hours if identified as critical by vendors or working exploit is known to exist?

    • A. No
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Same standard document.

  • T5Tier 1&2Security – Processes and Testing

    Are patches, updates or vendor mitigations for security vulnerabilities in other applications applied within one month of release?

    • A. No
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Same standard document.

  • T6CriticalTier 1&2Security – Processes and Testing

    Does your organisation have a formal, documented and implemented incident response plan which: • Defines roles and responsibilities for incident response; • Requires security, privacy and online safety incidents to be investigated, remediated, and recorded in a register with the following information at a minimum: o Date incident occurred; o Date incident discovered; o Description of the incident; o Actions taken in response to the incident; and o Name of person to whom the incident was reported?

    • A. No - none of the above (#T1, #T2)
    • B. Yes - some of the above (T2)
    • C. Yes - all of the above (T1)

    Our answerNeeds document

    C

    Incident response plan (security, privacy, online safety, AI) with roles. Register already exists with 5 entries.

  • T6ACriticalTier 1&2Security – Processes and Testing

    How frequently are incident response plans tested and updated? Conditional T2) (T6 – yes) B. Every 2 years (T2)

    • A. Annually and after major incidents (T1,
    • C. Other (#T1, # T2)

    Our answerNeeds document

    A

    Run one tabletop after the plan is written; date it.

  • T7CriticalTier 1&2Security – Processes and Testing

    When a data breach occurs, are affected customers and/or organisations notified as soon as possible after a data breach is discovered and given all relevant details (including affected individuals and what information was disclosed)?

    • A. No (#T1, #T2)
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    72-hour commitment in terms and school agreement.

  • T8Tier 1&2Security – Processes and Testing

    When a data loss/corruption event occurs, are affected customers and/or organisations notified as soon as possible after this is discovered and given all relevant details?

    • A. No – none of the above
    • B. Yes – some of the above (T2)
    • C. Yes – all of the above (T1, T2)

    Our answerNeeds document

    C

    Same clause covers data loss or corruption.

  • T8ATier 1&2Security – Processes and Testing

    Please specify how customers are notified Conditional (T8 – yes)

    No recommendation yet.

  • Q1Security – Plans and Quality

    (Question removed from 2021.1)

    No recommendation yet.

  • Q2Tier 1&2Security – Plans and Quality

    Does your organisation have a documented and implemented Business Continuity Plan for the service which includes: • Backup strategies (including automated, time synchronised backups, secure storage of all backups); • Restoration strategies (e.g., disaster recovery); and • Preservation strategies?

    • A. No
    • B. Yes - meets some requirements (T2)
    • C. Yes - meets all requirements (T1)

    Our answerNeeds document

    C

    Business continuity note: Supabase PITR + 90-day dumps + Vercel redundancy + founder key-person plan.

  • Q3Tier 1&2Security – Plans and Quality

    Does your organisation have a documented and implemented IT Change management process and supporting procedures which includes the following at a minimum: • Applicable criteria for entry to and exit from the change management process • Categorisation of IT change (e.g., Standard, Pre- Approved, Emergency, etc.); • Approval requirements for each category of IT change; • Assessment of potential security impacts; • Prerequisites for the IT change (e.g., the IT change has been tested in a non-production environment); • Documentation requirements in regard to the change (e.g., completion of a template in an IT change management tool, completion of a rollback plan, etc.); • Documentation that needs to be updated as a result of the change (e.g., as-built documentation, IT Disaster Recovery Plans, etc.); and • IT change communication processes (e.g., notifications to users)?

    • A. No change management process
    • B. Yes, change management process meets some requirements
    • C. Yes, change management process meets all requirements (T1, T2)

    Our answerNeeds document

    C

    Branch protection active (15 Sep), PR flow, preview deploys, rollback via Vercel. Write it down.

  • Q4Tier 1&2Security – Plans and Quality

    Does your organisation have a documented and implemented security, privacy and online safety risk management framework and supporting processes, which outlines at a minimum: • Scope and categorisation of information assets and systems; • Identification and assessment of risks/ threats, including those relating to the supply chain (e.g. from outsourced services that the solution relies on); • Identification of risk escalation thresholds, and risk acceptance delegations; • Selected and implemented controls to manage risks with the following details recorded in a risk register: o Identified security risks, categories and risk ratings; o Risk owner(s); o Mitigation actions with clear ownership, prioritisation, target implementation date; o Accepted risks (where applicable) and; o Residual risk ratings after implementing mitigation actions • Proactive monitoring and testing of information assets and systems to maintain the security posture on an ongoing basis?

    • A. No - none of the above
    • B. Yes - some of the above
    • C. Yes - all of the above (T1, T2)

    Our answerNeeds document

    B

    20-row risk register incl. AI provider dependency and key-person risk.

  • Q5CriticalTier 1&2Security – Plans and Quality

    Are all service application developments assessed as per a security testing methodology that is consistent with the guidance provided by the latest industry standard frameworks (e.g., Open Web Application Security Project (OWASP) Testing Guide v4.2, Building Security In Maturity Model (BSIMM))?

    • A. No (#T1, #T2)
    • B. Yes - security testing partially satisfies the guidance provided in an industry standard framework (please specify framework)
    • C. Yes - security testing fully satisfies the guidance provided in an industry standard framework (T1, T2) (please specify framework)

    Our answerNeeds document

    C, OWASP ASVS Level 1

    Secure SDLC document naming ASVS L1 with CI checks and annual pen test.

  • Q6Tier 1Security – Plans and Quality

    Does your organisation have a documented and implemented IT Asset management process including: • A register of all components that make up the service, including software, databases, middleware, infrastructure etc (their version numbers, patch levels and configuration); • An ICT equipment and media register that is maintained and regularly audited; • A directive that ICT equipment and media are secured when not in use; • The secure disposal of ICT equipment and media (including sanitising/removal of any data or secure destruction/shredding)?

    • A. No - none of the above
    • B. Yes - some of the above
    • C. Yes - all of the above (T1, T2)

    Our answerNeeds document

    B

    Asset register generated from package.json + Supabase + devices.

  • Q7CriticalTier 1&2Security – Plans and Quality

    Does your organisation have a documented and implemented information security policy that outlines the following at a minimum: • management direction and support for information security; • requirement to comply with applicable laws and regulations; • information security roles and corresponding responsibilities/accountabilities; and • requirement for communication to management to ensure they maintain an awareness of, and focus on, addressing privacy and security issues?

    • A. No (#T1)
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Signed information security policy with company name and number.

  • Q8Tier 1&2Security – Plans and Quality

    Does the service's application development have the following characteristics: • Environments are separated into at least development, testing and production environments; • Development and modification of software only takes place in development environments; • Unauthorised access to the authoritative software source is prevented; • Secure-by-design principles and secure programming practices are used as part of application development; • Privacy-by-design principles; and • Threat modelling is used in support of application development?

    • A. No – none of the above
    • B. Yes - some of the above
    • C. Yes - all of the above (T1, T2)

    Our answerNeeds document

    C

    Dev/test/prod separation (dev project 15 Sep), source in GitHub, one threat-modelling note for the AI pipeline.

  • I1Tier 1&2Security – Incidents

    Has the organisation, platform, or service had a recent security and/or privacy incident or breach in the last three years? If so were all incidents: • Managed according to the incident response plan and/or privacy breach management plan; • Notified to central agencies and affected individuals; and • Properly investigated with appropriate control improvements made as a result?

    • A. Yes - but not all requirements were met
    • B. Yes - all response, notification, investigation and improvement requirements were met (T1, T2) (please specify)
    • C. Yes - response, notification, investigation, remediation in progress (T1, T2) (please specify)
    • D. No known incidents or breaches have occurred (T1, T2)

    Our answerReady

    Declare the 15 Sep exposures

    Three exposures found and fixed during preparation, no evidence of access. Transparency is scored.

  • D1Tier 1&2Security – Data Deletion and Retention

    Are all data backups stored for a minimum of 3 months?

    • A. No
    • B. Yes (T1, T2)

    Our answerNeeds build

    B once 90-day dumps run

    PITR is 7 days. Nightly dump with 90-day lifecycle needs the DB password.

  • D2Tier 1&2Security – Data Deletion and Retention

    After customer data is deleted or removed from the service, is written confirmation or certification provided?

    • A. No
    • B. Yes - written confirmation or certification is provided, but only upon request from the customer
    • C. Yes - written confirmation or certification is automatically provided to the customer (T1, T2)

    Our answerNeeds build

    C

    Automated written confirmation on deletion: build the email.

  • D2ATier 1&2Security – Data Deletion and Retention

    Please specify the timeframe for removing or deleting customer data from the service.

    Our answerNeeds document

    30 days, backups purged within 90

    State it and make the purge true.

  • D3CriticalTier 1&2Security – Data Deletion and Retention

    Is the full restoration of backups tested at least once when initially implemented and each time major information technology infrastructure changes occur, and at least annually? (e.g., technology stack changes, vendor changes, platform changes)

    • A. No (#T1, #T2)
    • B. Yes (T1, T2)

    Our answerNeeds build

    B

    Restore one dump into a throwaway project, count rows, date it.

  • D4Tier 1&2Security – Data Deletion and Retention

    (Question removed 2023)

    No recommendation yet.

  • D5Tier 1&2Security – Data Deletion and Retention

    Does the organisation have a process to delete and remove inactive or dormant users and their related data?

    • A. No
    • B. Yes (T1, T2)

    Our answerNeeds build

    B, 24 months

    Dormant-account job to build.

  • D5ATier 1&2Security – Data Deletion and Retention

    Describe the process including how the organisation determines a user is inactive or dormant and the timeframes for deleting their data.

    No recommendation yet.

  • D6Tier 1&2Security – Data Deletion and Retention

    Is all user data within the service available for export in a reusable form? D. No

    • A. Yes (Self service at no cost)
    • B. Yes (Upon requests at no cost)
    • C. Yes (Upon requests with a cost)

    Our answerNeeds build

    A

    Self-service export to build.

  • CC1Tier 1&2Security – Compliance Controls

    Select the compliance certifications or security assessments that have been completed for the service and your organisation, or another organisation contracted by you to perform the development, maintenance and/or support of your solution (excluding the infrastructure provider e.g., AWS, Azure, Sendgrid)

    • A. ISO/IEC27001
    • B. SOC 2 Type II
    • C. FEDRAMP (NIST)
    • D. IRAP
    • E. Privacy confirmation (GDPR, SOPAA, Privacy Shield)
    • F. Cloud Security Alliance STAR
    • G. Cloud Vendor Assessment Tool (HECVAT)
    • H. 1EdTech TrustEd Apps(TM) Certification
    • I. ISO/IEC 27701 (Privacy Information Management)
    • J. HIPAA/HITECH (for handling protected health information)
    • K. HITRUST CSF (Common Security Framework)
    • L. Other (please specify)
    • M. None of the above

    Our answerReady

    None for Kuraplan; list providers'

    Attach Supabase/Vercel/AWS/Stripe certifications separately.

  • CC2CriticalTier 1&2Security – Compliance Controls

    Does the solution store, process, transmit, or otherwise handle cardholder data (CHD) or sensitive authentication data (SAD)?

    • A. Yes – The solution is PCI DSS validated. (T1, T2)
    • B. Yes – All payment functions are fully outsourced to a PCI DSS validated third party (please specify). (T1, T2)
    • C. No – The solution handles CHD/SAD but is not PCI DSS compliant.
    • D. N/A – The solution does not store, process, transmit, or interact with CHD/SAD. (T1, T2)

    Our answerReady

    B, Stripe

    Stripe Checkout only; card data never touches Kuraplan.

  • GO1CriticalTier 1&2Security – Governance

    Is there a nominated and suitably qualified individual within the organisation responsible for: • Coordinating and reporting on cyber security • Overseeing information security risk management including supply chain risks • Leading cyber security improvement activities • Overseeing cyber security awareness and training • Overseeing cyber security incident response

    • A. No (#T1, #T2)
    • B. Yes, with some of the specified responsibilities (specify the substantive role of the individual) (T2)
    • C. Yes, with all of the specified responsibilities (T1, T2) (specify the substantive role of the individual)

    Our answerNeeds document

    C

    Founder as security lead with written responsibilities.

  • GO2CriticalTier 1&2Security – Governance

    Is there a nominated Privacy Officer within the organisation who has a good understanding of privacy requirements and is responsible for: • Providing privacy advice internally. • Liaising with the Office of the Australian Information Commissioner and the New Zealand Office of the Privacy Commissioner (as relevant). • Co-ordinating the handling of internal and external privacy enquiries, privacy complaints and requests for access to, and correction of, personal information. • Maintaining a record of your organisation’s personal information holdings. • Assisting with the preparation of privacy impact assessments. • Measuring and documenting your organisation’s performance against its privacy management plan.

    • A. No (#T1, #T2)
    • AU PP
    • B. Yes, with some of the specified NZ PP responsibilities (specify the substantive role of the individual)
    • C. Yes, with all of the specified responsibilities (T1, T2) (specify the substantive role of the individual)

    Our answerNeeds document

    C

    Founder as privacy officer; publish the role and privacy@ contact.

  • GO3Tier 1&2Security – Governance

    Has responsibility for and ownership and accountability of critical system assets been assigned to individual/s in the organisation?

    • A. No
    • B. Yes (T1, T2)

    No recommendation yet.

  • GO4Tier 1&2Security – Governance

    What countries are your organisation's security and privacy operations teams and real-time monitoring and incident response systems located?

    • A. Entirely within Australia and/or New Zealand (please specify) (T1, T2)
    • B. From other countries (please specify country/s)
    • C. No defined security and privacy operations teams

    No recommendation yet.

Privacy

  • PA1Tier 1&2Privacy

    Are the terms of service/use made available free of charge, and, published on the internet or provided to customers prior to use of the service?

    • A. No
    • B. Yes (T1, T2)

    Our answerReady

    Yes

    Terms free and published.

  • PA2Tier 1&2Privacy

    As per the terms of service, what, if any, age restrictions apply to the use of the service?

    • A. Users must be over the age of 18
    • B. Users under the age of 18 can use the service with parent/guardian consent
    • C. No age restrictions apply (T1, T2)
    • D. Other (please specify)
    • E. NA - this service will not be used by students (T1, T2)

    Our answerNeeds document

    Adults only; students via teacher link under school authority

    State it in terms.

  • PA3Tier 1&2Privacy

    What are the specified definitions of intellectual property ownership, including copyright, in the terms of use for the service? (e.g., user generated content)? Include excerpt from terms of use.

    • A. Not specified
    • B. Service provider has ownership or licence to copy, alter, distribute, perform, display to all other users, third parties, affiliated organisations, etc. The service provider notifies users if their intellectual property is used for any of these purposes.
    • C. Service provider has ownership or licence to copy, alter, distribute, perform, display to all other users, third parties, affiliated organisations etc. The service provider does not notify users if their intellectual property is used for any of these purposes.
    • D. Service provider does not have ownership or licence to copy, alter, distribute, perform, display to all other users, third parties, affiliated organisations etc. (T1, T2)
    • E. N/A - There is no content that may be regarded as intellectual property (T1, T2)

    Our answerNeeds decision

    No ownership or broad licence over user content

    Check the shared-library clause in terms.

  • PA4Tier 1&2Privacy

    As per the terms of service, are users forewarned in the event the service provider wishes to terminate their account?

    • A. No
    • B. Yes (T1, T2)
    • C. N/A - Service provider does not terminate accounts (T1, T2)

    Our answerNeeds document

    Yes, users forewarned before termination

    Add the clause.

  • PR1CriticalTier 1&2Privacy – General

    Does the organisation have a Privacy Policy that is: • made available free of charge; • published online or otherwise provided to customers before they use or purchase the service?

    • A. No - one or more of the above is not met (#T1, #T2)
    • B. Yes - all requirements are met (T1, T2)

    Our answerNeeds build

    B

    Trust-site policy, free, linked from sign-up.

  • PR1ATier 1&2Privacy – General

    Enter the URL for the service’s Privacy Policy NZPP-3

    No recommendation yet.

  • PR1BCriticalTier 1&2Privacy – General

    Is the Privacy Policy kept up to date, reviewed at least annually, and revised as necessary to ensure accuracy, relevance and clear and accessible language?

    • A. No - no review process or version/date control (#T1, #T2)
    • B. Yes - reviewed at least annually (or on changes) and version/date are documented (T1, T2)

    Our answerNeeds document

    B

    Version and date on the policy; annual review entry.

  • PR1CCriticalTier 1&2Privacy – General

    How are users informed of the Privacy Policy before using or purchasing the service?

    • A. Users must review and agree to the Privacy Policy before use (e.g., checkbox, signature).
    • B. The Privacy Policy is shown to users before use; consent is implied if they continue using the service.
    • C. The Privacy Policy exists but users are not required to review or consent before use

    Our answerNeeds build

    A

    Add an explicit accept step at sign-up.

  • PR2CriticalTier 1&2Privacy – General

    Does the privacy policy or privacy collection notice for the service outline the following requirements about the collection and management of personal information at a minimum: • The kinds of personal information the entity collects and holds; • How the entity collects and holds personal information; • The purposes for which the entity collects, holds, uses, and discloses personal information; • The intended recipients of the information; • The consequences, if any, for an individual if all or part of the requested information is not provided; • How an individual may access personal information about the individual that is held by the entity and seek the correction of such information; • How an individual may complain about a breach of their privacy, and how the entity will handle such a complaint; • The company’s contact details for privacy concerns or requests; • Whether the entity is likely to disclose personal information to overseas recipients; and • If overseas disclosure is likely, the countries in which such recipients are likely to be located, if it is practicable to specify them.

    • A. No (#T1, #T2)
    • B. Yes - includes some of the above (#T1, #T2)
    • C. Yes - includes all of the above (T1, T2)

    Our answerNeeds document

    C

    Rewrite with each bullet as a literal heading (draft exists on the trust site; add recipients, consequences, contact details).

  • PR3ATier 1&2Privacy – General

    What mandatory information is collected by the service when school staff generate their own accounts for this service? Select all that apply. If not required, select N/A.

    • A. Title
    • NZPP-3
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level I Country or state/province
    • J. Role (for school leaders)
    • K. Evidence of identity
    • L. Racial or Ethnic Origin or Affiliation
    • M. Aboriginal or Torres Strait Islander status
    • N. Other (please specify):
    • O. N/A - school staff do not register their own accounts for this service

    Our answerReady

    Email, name

    Only mandatory fields for teachers.

  • PR3BTier 1&2Privacy – General

    What mandatory information is collected by the service when students generate their own accounts for this service? Select all that apply. If not required, select N/A.

    • A. Title
    • NZPP-3
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level
    • I. Country or state/province
    • J. Role (for school leaders)
    • K. Evidence of identity
    • L. Racial or Ethnic Origin or Affiliation
    • M. Aboriginal or Torres Strait Islander status
    • N. Other (please specify):
    • O. N/A - students do not register their own accounts for this service
    • P. N/A - students do not require accounts for this service

    No recommendation yet.

  • PR3CTier 1&2Privacy – General

    What mandatory information is collected by the service when parents generate their own accounts for this service? Select all that apply. If not required, select N/A. NOTE: This question relates to when parent accounts are required for school use of the service. If parent accounts are not required, select, “N/A parent accounts are not required for school use of this service”. N. N/A - parent accounts are not required for school use of this service O. N/A - parents do not register their own accounts for this service

    • A. Title
    • NZPP-3
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level
    • I. Country or state/province
    • J. Evidence of identity
    • K. Racial or Ethnic Origin or Affiliation
    • L. Aboriginal or Torres Strait Islander status
    • M. Other (please specify):

    No recommendation yet.

  • PR4ATier 1&2Privacy – General

    What mandatory information is collected by the service when a school-based administrator (or the service) generates accounts on behalf of school staff? Select all that apply. If not required, select N/A.

    • A. Title
    • NZPP-3
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level
    • I. Country or state/province
    • J. Evidence of identity
    • K. Racial or Ethnic Origin or Affiliation
    • L. Aboriginal or Torres Strait Islander status
    • M. Other (please specify):
    • N. N/A - school-based administrators or teachers or the service provider cannot generate accounts on behalf of staff

    No recommendation yet.

  • PR4BTier 1&2Privacy – General

    What mandatory information is collected by the service when a school-based administrator (or the service) generates accounts on behalf of students? Select all that apply. If not required, select N/A.

    • A. Title
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level
    • I. Country or state/province
    • J. Evidence of identity
    • K. Racial or Ethnic Origin or Affiliation
    • L. Aboriginal or Torres Strait Islander status
    • M. Other (please specify):
    • N. N/A - school based-administrators, teachers or the service provider cannot generate accounts on behalf of students

    No recommendation yet.

  • PR4CTier 1&2Privacy – General

    What mandatory information is collected by the service when a school-based administrator (or the service) generates accounts on behalf of parents? Select all that apply. If not required, select N/A.

    • A. Title
    • B. First name
    • C. Surname
    • D. Email address
    • E. Gender
    • F. Date of birth (i.e., dd/mm/yy)
    • G. Age, month and year of birth, or year of birth
    • H. Year level
    • I. Country or state/province
    • J. Evidence of identity
    • K. Racial or Ethnic Origin or Affiliation
    • L. Aboriginal or Torres Strait Islander status
    • M. Other (please specify):
    • N. N/A - school based-administrators, teachers or the service provider cannot generate accounts on behalf of parents

    No recommendation yet.

  • PR5Tier 1&2Privacy – General

    Do the terms of use for the service (ToS) or the privacy policy (PP) require complete and accurate information to be entered when registering accounts for the service (e.g., use of pseudonym or de-identified information is prohibited)? Please include excerpt from the terms of service or privacy policy.

    • A. Yes (please provide excerpt from ToS or PP)
    • B. No (please provide excerpt from ToS or PP) (T1, T2)

    Our answerNeeds document

    Pseudonyms allowed

    Terms must not require real names.

  • PR6Tier 1&2Privacy – General

    Are customers/users offered anonymity and/or pseudonymity when dealing with the service provider in some circumstances (e.g., providing feedback)?

    • A. No
    • B. Yes, please specify circumstances (T1, T2)

    Our answerReady

    Anonymous feedback available

    Contact form without login.

  • PR7Tier 1&2Privacy – General

    Are mandatory fields clearly distinguished from optional fields during the standard account registration process?

    • A. No
    • NZPP-3
    • B. Yes (T1, T2)

    No recommendation yet.

  • PR8Tier 1&2Privacy – General

    Are mandatory fields clearly distinguished from optional fields when schools, teachers, or the service register accounts on behalf of other users (e.g., students, staff, or parents)?

    • A. No
    • NZPP-3
    • B. Yes (T1, T2)

    No recommendation yet.

  • PR9Tier 1&2Privacy – General

    If unsolicited personal information is provided to the service (e.g., when existing customer data is uploaded to the service), is the information destroyed or de-identified as soon as practicable if it is lawful to do so?

    • A. No
    • NZPP-9
    • B. Yes (T1, T2) APP4 QPP4

    Our answerNeeds document

    Destroyed promptly

    No CSV import today; state the rule for any future import.

  • PR10CriticalTier 1&2Privacy – General

    Does your organisation share user data with third parties in any circumstance other than the following? If yes, please specify. • the individual has consented to the use or disclosure of the information; • the use or disclosure of the information is required or authorised by or under a law or a court/tribunal order in the customer’s country; • the use or disclosure is required or permitted under privacy legislation in the customer’s country; or • the entity reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body? For service in Australia, refer to the Australian Privacy Principles, as well as the permitted general situations and permitted health situations. For service in New Zealand, refer to the Privacy Principles and information sharing provisions in the Privacy Act 2020, as well as the Oranga Tamariki Act 1989 and the Family Violence Act 2018

    • A. Yes (please specify) (#T1, #T2)
    • B. No (T1, T2)

    Our answerNeeds decision

    B

    True once ad-conversion events leave the product (decision pending).

  • PR11Tier 1&2Privacy – General

    Can users opt-in or opt-out to the service's commercial mailing list/promotional/marketing communications (e.g. email mailing lists)? Commercial mailing lists are those that are used for the purpose of distributing sales and marketing and promotional materials, including (but not limited to) competitions, education research related to the product, and end user feedback. Commercial mailing lists do not include lists used for the purpose of sending important service information, such as notifications of service disruption, data breach or loss; upgrade notifications; and subscription renewals.

    • A. Users cannot opt-out. Users are automatically subscribed to receive commercial/promotional/marketing communications.
    • B. Users can opt-out. Some or all users are automatically subscribed but can opt-out after the fact
    • C. Users can opt-in. Users do not receive commercial/promotional/marketing communications unless they explicitly opt-in (T1, T2)
    • D. N/A – The service or organisation does not have any commercial/promotional/marketing communications (T1, T2)

    Our answerNeeds decision

    C

    Express opt-in question at profile setup; consent flag; edge function fixed. Decision pending.

  • PR12CriticalTier 1&2Privacy – General

    Does the service adopt government related identifiers of individuals as its own identifier of the individual or use or disclose government related identifiers for any reasons other than the list below: • The government related identifier is required or authorised by or under a law or a court/tribunal order within the customer’s country; • Use or disclosure is necessary for the organisation to verify the identity of the individual for the purposes of the organisation's activities or functions; • Use or disclosure is necessary for the organisation to fulfil its obligations to a government agency or education authority within the customer’s country; • Use or disclosure is required or authorised by or under a law or a court/tribunal order within the customer’s country; • The organisation reasonably believes the use or disclosure of the identifier is reasonably necessary for one or more enforcement related activities; • The identifier, organisation or circumstances are prescribed by regulations?

    • A. Yes (provide details of the identifier(s) and how each is used) (#T1, #T2)
    • B. No (T1, T2)

    Our answerReady

    B

    No government identifiers, verified 15 Sep.

  • PR13CriticalTier 1&2Privacy – General

    Does your organisation have a process which allows customers to request the service to provide access to, correct, or delete all personal information relating to them?

    • A. No (#T1, #T2)
    • B. Yes - with a cost and resolved outside of 3 months
    • C. Yes - with a cost and resolved within 3 months
    • D. Yes - free of charge and resolved outside of 3 months (T2)
    • E. Yes - free of charge and resolved within 3 months (T1, T2)
    • F. NA - service does not collect personal information (T1, T2)

    Our answerNeeds document

    E

    Free, within 30 days. Write the process.

  • PR14CriticalPrivacy – General

    Does the service provide any discovery functionality which allows users from one school to find, access or discover users or personal information from another school, or organisation? Examples include enabled searching (by user, user details or resources), or data sharing (e.g. to support student transfer) or integration (e.g. for analytics) between customers (e.g. different schools). Select all that apply.

    • A. No discovery functionality exists within
    • NZPP-11 service (T1,T2)
    • B. Discovery functionality can be restricted to the user’s current school/year level/class
    • C. Discovery functionality is disabled by default
    • D. An administrator can restrict discovery functionality at the user level (i.e. allow some but not all users access discovery functionality)
    • E. Discovery is possible, but none of the controls above are available (#T1, #T2)

    Our answerReady

    A

    Verified 15 Sep 2026: both resource listing functions filter to the caller's own rows or same-school shared rows; the underlying view is readable by the service role only (anon and logged-in sessions get permission denied). No user directory or people search. Evidence 02-access/2026-09-15-PR14.

  • PR15Privacy – General

    Does the service capture a user’s location data?

    • A. No location data processed (T1, T2)
    • B. The service must capture user location data to function. Location data is captured with a user’s explicit consent (T1, T2)
    • C. The service must capture user location data to function. Location data is captured without a user’s explicit consent.
    • D. The service does not require user location data to function, but does capture it with a user’s explicit consent.
    • E. The service does not require user location data to function, but does capture it without a user’s explicit consent.

    Our answerReady

    IP-derived country only, not stored as location

    State it.

  • PR16CriticalTier 1&2Privacy – General

    How does the organisation notify users when updates occur to the Privacy Policy and the Terms and Conditions?

    • A. Users are sent a notification when updates are made to the Privacy Policy and Terms and Conditions
    • B. Users are sent a notification prior to updates being made to the Privacy Policy and Terms and Conditions (please specify minimum timeframe)
    • C. Users are required to review and explicitly consent to the latest Privacy Policy and Terms and Conditions prior to being able to continue using the service. (T1, T2)
    • D. None of the above (#T1)

    Our answerNeeds build

    C

    Re-acceptance gate on policy version change: build.

  • PR17CriticalTier 1&2Privacy – General

    Does the Privacy Policy or other published document describe all of the service's sub processors including information on: • The name of the sub processor and its organisation; • Contact information of the sub processor (e.g. website URL, email address); • The data types disclosed to the sub processor including the purpose of the sub processor; • The lawful basis for processing the data where applicable; • Countries where data may be processed in or stored.

    • A. Yes - All of the above (T1) (please provide link)
    • B. Yes - Some of the above including name of the sub processor, data types disclosed, and location of processing (T2) (please provide link)
    • C. No (#T1, #T2)

    Our answerNeeds document

    A

    trust.kuraplan.com/subprocessors; add the lawful-basis column.

  • PR18Tier 1&2Privacy – General

    In addition to any published sub processors, does the organisation share, publish or provide access to any user data (including where de-identified, aggregated, etc) to a third party?

    • A. Yes (Please specify)
    • B. No (T1, T2)

    Our answerReady

    B

    No sale.

  • PR19Tier 1&2Privacy – General

    Does the organisation or service share, publish, or provide access to any personal information or aggregated/de-identified user data to third parties for advertising, market research, profiling, or similar purposes?

    • A. No personal information or aggregated/de-identified data is shared, published, or provided to third parties for these purposes
    • B. Aggregated or de-identified user data may be shared with third parties (no personal information is shared) (please specify)
    • C. Personal information may be shared with third parties for advertising, market research, profiling, or similar purposes (please specify)
    • D. Both personal information and aggregated/de-identified data may be shared with third parties for these purposes (please specify)

    Our answerNeeds decision

    A

    True once ad plumbing leaves the product.

  • PR20Tier 1&2Privacy – General

    Does the organisation or service use, share, publish or provide access to any user data (including where de- identified, aggregated, etc) for use in artificial intelligence or machine learning (including training or developing of AI or ML models)?

    • A. Yes (Please specify)
    • B. No (T1, T2)

    Our answerReady

    B

    No training on user data; provider no-training terms in place.

  • PF1Tier AllPrivacy – Functionality

    When using the service, are any users exposed to advertising, marketing and/or offers?

    • A. Yes
    • B. No (T1, T2)

    Our answerReady

    B

    No advertising inside the product; own-plan upsells only.

  • PF2Tier 1&2Privacy – Functionality

    Does the service provide functionality that allows school- based administrator accounts to control role-based access for school users (e.g., staff or students) in order to restrict access to stored information and/or functionality within the system?

    • A. No
    • B. Yes, please provide details (T1, T2)
    • C. N/A (T1, T2)

    Our answerNeeds build

    Yes via school policy control plane

    Build the school-admin toggles.

  • PF3Tier 1&2Privacy – Functionality

    Does the registration of an account or use of the service generate a user 'profile' within the service, and if so, can visibility be restricted (e.g., made private or restricted to known users)? B. Profile is generated, and user or administrator can restrict visibility of their profile C. Profile is generated but only visible to user (e.g., visibility is restricted by default) (T1, T2) D. No user profile is generated (T1, T2)

    • A. Profile is generated, but user or administrator cannot restrict visibility of their profile

    Our answerReady

    No public profiles

    True.

  • PF4Tier AllPrivacy – Functionality

    Select all functionality available within the service. Informational only, used to generate subsequent questions. R. Data aggregation, analytics, insights and S. Assessment or collection of health and T. Other (please specify) U. None of the above

    • A. Forms, surveys and eSignatures
    • B. Online meetings, video conferencing, audio conferencing
    • C. Remote access tools
    • D. Screen Sharing and/or Screen recording
    • E. Chat / Instant Messaging
    • F. Commenting and communities/forum
    • G. Quiz, poll, flashcard creation and/or distribution
    • H. File download, including executable, developer tools, images etc.
    • I. Direct email
    • J. File upload and storage, and file sharing and collaboration
    • K. Content creation and collaboration
    • L. Content libraries
    • M. Notifications and alerts
    • N. Online learning activities, assessments and/or games
    • O. Administrative support services and records management
    • P. Data distribution, data broker, integration platforms as a service
    • Q. Authentication as a service and identity providers reporting well-being information including socio- emotional factors (e.g., physical and mental health, well-being, behaviour)

    Our answerReady

    Content creation; content libraries; quiz creation; notifications; file upload; learning activities

    Do not select chat/forums/video/remote access.

  • PF5Privacy – Functionality

    In relation to the form, survey and/or eSignature functionality, select which features are offered within the service. Select all that apply.

    • A. Online forms - service provider generated, non-editable
    • B. Online forms - customisable / editable / user generated
    • C. Surveys - service provider generated, non- editable
    • D. Surveys - customisable / editable / user generated
    • E. eSignatures
    • F. Forms/surveys can be distributed and/or shared via linked social media accounts (Facebook, Twitter etc.)
    • G. Forms/surveys can be shared as templates for re-use by others

    No recommendation yet.

  • PF6CriticalPrivacy – Functionality

    In relation to the online meeting, video conference, audio conferencing and/or livestreaming functionality available within the service, select all that apply.

    • A. Access to sessions can be made available to the public
    • B. Access to sessions can be made private (e.g., access to sessions is invitation only)
    • C. Participant details can be displayed to all session participants
    • D. Participants can be displayed with de- identified/anonymous details or kept private
    • E. Sessions can be recorded and made available to the public
    • F. Sessions can be recorded and made private (e.g., participants only)
    • G. Audit logs are not kept for all recordings (#T1, #T2)
    • H. Participants are not notified if they are participating in a recorded session (e.g., via on screen prompt) (#T1, #T2)

    No recommendation yet.

  • PF7CriticalPrivacy – Functionality

    In relation to the remote access tools available within the service, select all that apply.

    • A. Remote access tools can be disabled by an administrator or moderator
    • B. Remote access sessions can be initiated without the agreement of the user (#T1, #T2)
    • C. Users cannot take back control during remote access sessions (#T1, #T2)
    • D. Users cannot terminate remote access sessions once initiated (#T1, #T2)
    • E. Onscreen notification is displayed throughout remote access sessions
    • F. Remote access sessions are not logged (#T1, #T2)

    No recommendation yet.

  • PF8CriticalPrivacy – Functionality

    In relation to the screen sharing and/or screen recording functionality available within the service, select all that apply.

    • A. Use of screen sharing functionality is disabled by default
    • B. Screen sharing and/or screen recording can be disabled by an administrator or moderator
    • C. Screen sharing sessions and/or screen recording are initiated and/or accepted by the user who is sharing their screen
    • D. Screen sharing and/or screen recording sessions are not logged (#T1, #T2)
    • E. Screen recordings can be shared with other users on the service

    No recommendation yet.

  • PF9APrivacy – Functionality

    How does your service moderate chats/messages for inappropriate content? (Select all that apply)

    • A. The service moderates chat/messages using a profanity filter
    • B. The service moderates chat/instant messaging and reserves the right to remove posts and/or users that breach the Terms of Use
    • C. Users can report chat/instant messaging that breaches the Terms of Use
    • D. Other (please specify)
    • E. None of the above

    No recommendation yet.

  • PF9BPrivacy – Functionality

    Can non-account holders chat and communicate with account holders (i.e., no log in is required to participate in chat/messaging)?

    • A. Yes
    • B. No (T1, T2)

    No recommendation yet.

  • PF9CPrivacy – Functionality

    What controls are in place to restrict communication and access to other users?

    • A. Communication can be limited to restricted groups only (e.g., class, year level)
    • B. Chat/instant messaging is visible to an administrator (e.g., teacher) in real time
    • C. Chat/instant messaging can be disabled by an administrator or moderator
    • D. Other (please specify)
    • E. None of the above

    No recommendation yet.

  • PF9DCriticalPrivacy – Functionality

    Are audit logs of chat/instant messaging available including all of the following information: • account identifier of the sender and recipient; • timestamp of the message or event, and • whether the message was removed (if applicable).

    • A. Yes (T1, T2)
    • B. No (T1#, T2#)

    No recommendation yet.

  • PF10APrivacy – Functionality

    How does your service moderate your commenting and communities/forums functionality for inappropriate content? (Select all that apply)

    • A. The service applies a profanity filter prior to publishing
    • B. The service moderates comments and reserves the right to remove posts and/or users that breach the Terms of Use
    • C. Users can report comments that breach the service's Terms of Use
    • D. Comments must be approved by an administrator or the service prior to publishing
    • E. Other (please specify)
    • F. None of the above

    No recommendation yet.

  • PF10BPrivacy – Functionality

    Can non-account holders can post comments and communicate with account holders (i.e., no log in is required to post or reply to comments in communities/forums):

    • A. Yes
    • B. No (T1, T2)

    No recommendation yet.

  • PF10CPrivacy – Functionality

    What controls are in place to restrict communication and access to other users?

    • A. Commenting can be disabled by an administrator/moderator
    • B. An administrator can control what users can comment on and which users can comment (e.g., a teacher can restrict students to only comment on the work of classmates)
    • C. Users can upload files or share projects or files in forums/communities
    • D. Other (please specify)
    • E. None of the above

    No recommendation yet.

  • PF10DCriticalPrivacy – Functionality

    Are audit logs for commenting and/or community forums available including all of the following information: • account identifier of the sender and recipient; • timestamp of the post or event, and • whether the post was removed (if applicable)

    • A. Yes (T1, T2)
    • B. No (T1#, T2#)

    No recommendation yet.

  • PF11Privacy – Functionality

    In relation to the quiz, poll and flashcard functionality, select which features are offered within the service. Select all that apply.

    • A. Quizzes - service provider generated, non- editable
    • B. Polls - service provider generated, non- editable
    • C. Flashcards - service provider generated, non-editable
    • D. Quizzes - customisable / user generated
    • E. Polls - customisable / user generated
    • F. Flashcards - customisable / user generated
    • G. Quizzes, polls and/or flashcards can be shared as templates for re-use by others

    No recommendation yet.

  • PF12Privacy – Functionality

    (Question removed from 2021.1)

    No recommendation yet.

  • PF13Privacy – Functionality

    In relation to the file download functionality available, select all files types that can be downloaded within the service. E. Video files (e.g., .avi, .mov, .wmv, .gif) F. Database files (e.g., .dat, .csv, .log, .mdb) G. Other

    • A. Executable files and/or code (e.g., .exe)
    • B. Desktop publishing files (e.g., .doc, .pdf, .ppt)
    • C. Image files (e.g., .png, .jpg, .jpeg)
    • D. Audio files (e.g., .mp3, .wma, .wav)

    Our answerReady

    PDF, DOCX, PPTX, PNG

    No executables.

  • PF14Privacy – Functionality

    (Question removed from 2023.1)

    No recommendation yet.

  • PF15Privacy – Functionality

    When sending correspondence via the service on behalf of the school, how does the service send email communication to the school’s recipients/audience? Select all that apply.

    • A. Sent from the school user’s registered email address
    • B. Sent from the service’s domain (e.g., user@servicename.com)
    • C. Sent from unverified, anonymous or invalid email addresses
    • D. Other

    Our answerReady

    All email from our verified domains

    SPF, DKIM and DMARC (p=reject) on send.kuraplan.com verified 16 Sep 2026; apex DMARC at quarantine, moving to reject after a week of clean reports. Evidence 01-infrastructure/2026-09-16-dns-snapshot.

  • PF16Privacy – Functionality

    What, if any, third party products are used to provide the file upload and storage functionality within the service? Select all that apply.

    • A. YouTube
    • B. Vimeo
    • C. Flickr
    • D. Image Shack
    • E. Picasa
    • F. Other image and video streaming services
    • G. DropBox
    • H. Google Drive
    • I. OneDrive
    • J. Box
    • K. iCloud
    • L. Other cloud storage and file sharing
    • M. No third-party products are used

    Our answerReady

    Supabase Storage on AWS

    No consumer drives.

  • PF17Privacy – Functionality

    In relation to the file upload and sharing functionality available within the service, select all that apply.

    • A. Users can download files uploaded to the service by other users
    • B. Authors have control over who can view and/or edit their files
    • C. Administrators (e.g., teachers) can restrict who can view and/or edit users' files
    • D. Administrators can disable file sharing
    • E. None of the above
    • F. Not applicable – file sharing is not supported

    No recommendation yet.

  • PF18Privacy – Functionality

    (Question removed from 2023.1)

    No recommendation yet.

  • PF19Privacy – Functionality

    In relation to the content creation functionality available within the service, select all that apply.

    • A. Users can share their content (e.g., via direct urls)
    • B. Users have control over who can view or edit their content
    • C. Administrators can restrict who can view and/or edit users' content
    • D. Administrators can disable sharing of users' content
    • E. None of the above

    Our answerNeeds build

    Private by default; author controls sharing

    Add school-admin restrict.

  • PF20Privacy – Functionality

    Select the response option which best describes the publication of user generated content. Publication means visible to all members and/or visitors to the service.

    • A. User generated content can be published to the service but no privacy settings can be applied
    • B. User generated content can be published to the service and privacy settings can be applied
    • C. User generated content cannot be published to the service

    No recommendation yet.

  • PF21Privacy – Functionality

    In relation to the content libraries available within the service, select all that apply. Content may include:

    • A. Educational or curriculum aligned content and activities
    • B. Non-educational content and activities
    • C. Template libraries (e.g., presentations, web design, surveys etc.)
    • D. Image, video and audio libraries
    • E. Search results that are not filtered based on user characteristics (e.g., age, year level, user type etc.)
    • F. None of the above

    No recommendation yet.

  • PF22Privacy – Functionality

    Who can publish content to content libraries within this service (i.e., users or service provider); and is content subject to moderation to ensure users are not B. Service provider generated content without exposed to information, including images, video, text moderation and/or recordings, which may be deemed: C. User generated content with moderation • Offensive by a reasonable member of the school D. User generated content without community (e.g., nudity, pornography, graphic content, moderation profanity, racist, sexist etc. and/or • Inappropriate for users under 18 years? Moderation may include: • The service reserves the right to remove content that breaches the Terms of Use • The service applies a profanity filter • The service has an implemented assurance procedure to ensure content conforms to quality standards prior to publication • Users can report content that breaches the Terms of Use Select all that apply.

    • A. Service provider generated content with moderation

    Our answerNeeds build

    C, with moderation

    Report button + takedown SLA + name scan: build.

  • PF23Privacy – Functionality

    In relation to the notification and alert functionality available within the service, select all that apply.

    • A. Notifications and alerts can be one-way (broadcast)
    • B. Notifications and alerts can be two-way e.g., parents/recipients can respond to notifications and alerts
    • C. Notifications can be via email
    • D. Notifications can be via SMS
    • E. Notifications can be via push notifications
    • F. Notifications and alerts can be disabled by an administrator/moderator
    • G. For each notification and/or alert, the school and/or users can specify and/or limit the audience
    • H. The school and/or user can create and manage a subscriber group, and only members of this group can receive notifications and/or alerts from the school and/or user

    Our answerReady

    Email only, one-way, can be disabled

    True.

  • PF24Privacy – Functionality

    (Question removed from 2021.1)

    No recommendation yet.

  • PF25Privacy – Functionality

    In relation to the online learning activities, assessment and/or game functionality available within the service, select all that apply.

    • A. The service provides standardised testing
    • B. The teacher or user can create their own online learning activities and/or games.
    • C. Answers can include pre-defined response options (e.g., multiple choice, Likert scales etc.)
    • D. Answers are numerical free text fields (e.g., 0-9)
    • E. Answers are short response free text fields (e.g., typing, equations, units of measurement, spelling and vocabulary)
    • F. Answers can include long response free text fields (e.g., sentences, paragraphs, essays etc.)
    • G. Answers can include file uploads (e.g. uploading a word document, image file etc)
    • H. Data analysis, analytics and/or reporting is generated
    • I. Data analytics and/or reporting can be sent to parents via the service.
    • J. Answers can include audio or video (e.g. capture from the microphone or camera)
    • K. Notes or comments can be made against a response, learning activity, assessment and/or game

    Our answerReady

    Learning activities; results generated and stored

    Declare Activities; results never published.

  • PF26Privacy – Functionality

    Select the response option which best describes the publication of results on the service. Results are considered to be published if they are visible to anyone other than the owner of the results.

    • A. Student results can be published on the service but privacy settings cannot be applied.
    • B. Student results can be published on the service and privacy settings can be applied.
    • C. Student results cannot be published.

    Our answerReady

    C

    Student results cannot be published. Verify no public results page.

  • PF27Privacy – Functionality

    In relation to any other functionality that is offered by the service, select all that apply. processing systems C. Enrolment management D. Student information, student management system, school administration or student administration system E. Customer relationship management F. Ticketing systems G. Electronic document and records management systems H. Data integration, aggregation, data broker, data hub, data distribution hub I. Library Management J. Visitor Management K. Event management, bookings, online ordering or fundraising L. Subject selection M. Class formation N. Assignment submission O. Plagiarism detection P. Roll marking Q. Absence reporting and notifications R. Timetabling S. Academic reporting T. Other (please specify) U. None of the above

    • A. Online ordering
    • B. Financial management or payment

    Our answerReady

    None of the listed SIS/LMS functions

    Planner and lesson planning described under 'other'.

  • PF28Privacy – Functionality

    What names do you, as the service provider, give to the Informational question- used to inform QA various modules available within the service? and data assets disclosed to service.

    No recommendation yet.

  • PF29Privacy – Functionality

    What additional student data - other than that which is For each indicate mandatory, optional or not mandatory to register an account - can be provided to / collected: collected by the service when used for its intended purpose? Please indicate whether this data field is mandatory or optional.

    • A. Protection details
    • B. Legal custodian arrangements
    • C. Out of home care status
    • D. Records of behaviour incidents
    • E. Behavioural observations/notes
    • F. Support arrangements
    • G. Professional case notes
    • H. Consent
    • I. Attendance, including reason for absence
    • J. Records of interview and/or contact
    • K. Academic results
    • L. Academic testing
    • M. Personality profiling, career goals and/or interests
    • N. Commonwealth Unique Student Identifier (AU) or National Student Number (NZ)
    • O. Timetabling
    • P. Emergency contacts
    • Q. Other (please specify)
    • R. None of the above

    Our answerReady

    None of the above

    No sensitive student data fields.

  • PF30Privacy – Functionality

    When a school uses this service, what additional For each indicate mandatory, optional or not information (beyond what’s required to set up an collected: account) may be collected about students, staff, or parents? This question is only about school use, exclude any data collected during personal use by parents. For each data asset, please specify whether it relates to student, staff, or parent. Select N/A if no data is collected.

    • A. Medical details
    • B. Well-being information
    • C. Year level
    • D. Class name
    • E. School name
    • F. Works
    • G. Image
    • H. Video or audio recording
    • I. Email address
    • J. First name
    • K. Surname
    • L. Date of Birth
    • M. Age, month and year of birth, or year of birth
    • N. Home address
    • O. Phone number
    • P. Identification documentation
    • Q. Electronic signature
    • R. Cultural and citizenship details, racial or ethnic origin
    • S. Religion
    • T. Gender
    • U. Languages spoken
    • V. Username - determined by the user
    • W. Country or State/province
    • X. Responses - online learning, surveys, forms
    • Y. Resume, CV, applications, references
    • Z. Certificates and accreditation AA. User location data AB. N/A

    Our answerNeeds build

    First name, year level, school (optional)

    Remove learner notes/interests first.

  • PF31Privacy – Functionality

    What, if any, other data not listed above can be disclosed Free text field (informational) to or collected by the service if used for its intended purpose? Please specify if data relates to student, staff or parent and whether it is mandatory or optional.

    No recommendation yet.

  • PF37Privacy – Functionality

    In relation to the assessment or collection of health and well-being information through functionality available within the service, select all that apply:

    • A. Online forms – service provider generated, non-editable
    • B. Surveys – service provider generated, non- editable
    • C. Quizzes – service provider generated, non- editable
    • D. Polls – service provider generated, non- editable
    • E. Learning activities and/or game-based assessment
    • F. Diagnostic and/or standardised testing
    • G. Online forms – customisable / user generated
    • H. Surveys – customisable / user generated
    • I. Quizzes – customisable / user generated
    • J. Polls – customisable / user generated
    • K. Learning activities and/or game-based assessment – customisable / user generated
    • N. Data analysis, analytics and/or reporting is generated for users based on their responses
    • P. Well-being data analytics and/or reporting can be sent to parents via the service.

    No recommendation yet.

  • PF37APrivacy – Functionality

    Does the service have in-built monitoring and/or reporting tools for schools to identify respondents who may require follow up or additional support?

    • A. In-built monitoring and/or reporting tools identify respondents who may require follow- up or additional support - (please specify)
    • B. No in-built monitoring and/or reporting tools are provided to identify respondents who may require follow-up or additional support.

    No recommendation yet.

  • PF38Privacy – Functionality

    In relation to the response options available within the service to assess or collect health and well-being information, select all that apply:

    • A. Responses can include pre-defined response options (e.g., multiple choice, Likert scales etc.)
    • B. Responses are numerical free text fields (e.g., 0-9)
    • C. Responses are short response free text fields (e.g., typing, equations, units of measurement, spelling, and vocabulary)
    • D. Responses can include long response free text fields (e.g., sentences, paragraphs, essays etc.)
    • E. Users can request further assistance or to talk to someone.
    • F. Users can request further assistance or to talk to someone and this automatically notifies the school-nominated staff member.
    • G. Users are de-identified and response data is aggregated/summarised so users and respondent data and reports are anonymous.
    • H. Response data is aggregated/summarised so respondent data and reports do not identify the user.
    • I. Respondent data and reports identify individuals for the purpose of monitoring, action and follow-up.
    • J. Other

    No recommendation yet.

  • PF39Tier 1&2Privacy – Functionality

    With regards to personal information in the service, does the service log the following events: • Creation • Access • Modification • Deletion

    • A. No – None of the above
    • QPP11/IPP4
    • B. Yes – Some of the above NZISM 16.6.7
    • C. Yes – All of the above (T1, T2) NZISM 16.6.10

    Our answerNeeds build

    C

    Audit logging of personal-data records: add pgaudit or triggers.

  • PF51Privacy – Functionality

    In relation to file upload functionality within the service, are the principles and techniques from the OWASP followed?

    • A. No - None of the principles or techniques are followed
    • B. Yes - Only some of the principles and techniques are followed
    • C. Yes - Majority of the principles and techniques are followed excluding AV scanning
    • D. Yes - Majority of the principles and techniques are followed including AV scanning
    • E. Yes - All of the principles and techniques are followed (T1, T2)

    Our answerNeeds build

    E

    Type/size validation, random names exist; add AV scanning.

  • PF52Privacy – Functionality

    Does the service automatically remove or sanitise potentially sensitive metadata (such as EXIF geolocation, device identifiers, and timestamps) from user-uploaded files?

    • A. Yes – All identifying or sensitive metadata is automatically removed or sanitised on upload.
    • B. Partially – Sensitive metadata (such as geolocation) is removed, but non-identifying metadata needed for functionality is retained. (please specify)
    • C. No – Metadata is retained only where the user uploading has provided explicit, informed consent for a feature that requires it. (please specify)
    • D. No – Metadata is retained because it is technically required for core service functionality and cannot be removed. (please specify)
    • E. N/A – The service does not accept user- uploaded files.

    No recommendation yet.

  • PF53Privacy – Functionality

    Does the service offer support for passwordless authentication or biometric authentication?

    • A. Yes (please specify)
    • B. No

    No recommendation yet.

  • PF54Privacy – Functionality

    Can authentication flows be customised?

    • A. Yes (please specify)
    • B. No

    No recommendation yet.

  • PF55Privacy – Functionality

    Does the service provide audit logs for authentication events?

    • A. Yes
    • B. No

    No recommendation yet.

  • PF56Privacy – Functionality

    Are security questions customisable by the organisation Free text or predefined? Data integration, aggregation, data broker, data hub, data distribution hub control questions (PF32, PF33, PF35, PF36, PF40-PF50)

    No recommendation yet.

  • PF32Privacy – Functionality

    In relation to the data integration, aggregation, data broker, data hub, data distribution hub functionality, does the service (the collector of data/ data aggregator / data broker) assume ownership of any data transferred to, or transiting through, the service?

    • A. Yes
    • B. No (T1, T2)

    No recommendation yet.

  • PF33Privacy – Functionality

    In relation to the sharing of data with any third party (any service which receives data of any form from the service), are enforceable, written agreements in place with data suppliers or recipients that covers: • the purpose for data sharing; • the scope of data to be shared (e.g., academic results); • the scale of data sharing (e.g., current student records only, or a specific year level); • the security and privacy controls in place in recipient systems; and • ownership of data. Furthermore, data agreements are updated to reflect changes in any of the above?

    • A. No
    • B. Yes - Some of the above but data agreements not updated
    • C. Yes - Some of the above with data agreements updated
    • D. Yes (T1, T2)

    No recommendation yet.

  • PF34Privacy – Functionality

    Retired

    No recommendation yet.

  • PF35Privacy – Functionality

    Who authorises the transfer of data, including the data Select all that apply: scope (e.g., student academic results) and scale (e.g., only year 8 students) from the service (data integration/aggregation service, data broker, data hub, data distribution hub) to recipient third party systems: B. Data sharing can be controlled by the data aggregator (service being assessed) C. Data sharing can be controlled by the data recipient

    • A. Data sharing can be controlled by the customer (school, school system or jurisdiction) (T1, T2)

    No recommendation yet.

  • PF36CriticalPrivacy – Functionality

    When a data breach or data loss event occurs in third party recipient systems, who notifies the customer (e.g., school, school jurisdiction or school system)?

    • A. Data aggregator notifies customer as soon as possible after discovery and provides all relevant details (T1, T2).
    • B. Data aggregator notifies customer without commitment to timeframe and/or details not provided.
    • C. Third party service notifies customer as soon as possible after discovery and provides all relevant details.
    • D. Third party service notifies customer without commitment to timeframe and/or details not provided.
    • E. Unknown (#T1, #T2)
    • F. No notification of customer occurs (#T1, #T2)

    Our answerReady

    N/A

    No data-hub relaying between school systems.

  • PF40Privacy – Functionality

    Does your service offer enterprise level controls (for example schools that belong to an owning higher authority (e.g. a Department or Education Authority))?

    • A. No
    • B. Yes – two or more levels (e.g. school level controls and Departmental controls)
    • C. Yes – two or more levels with Departmental controls overriding school level controls (T1, T2)

    No recommendation yet.

  • PF41Privacy – Functionality

    When your service ingests data from a customer’s source system, does the customer have the ability to specify and restrict the exact data elements/fields (i.e. ‘select’ and ‘where’ clauses) shared with your service?

    • A. No (please specify)
    • B. Yes - source system extract can be defined by the school only
    • C. Yes - source system extracts can be defined by the school or higher (enterprise/departmental) authority. Higher authority settings can be altered by the school
    • D. Yes - source system extracts can be defined by the school or higher (enterprise/departmental) authority. Higher authority settings cannot be altered by the school (T1, T2)

    No recommendation yet.

  • PF42Privacy – Functionality

    Does your service offer the ability for the customer to restrict which recipient systems are available for integration?

    • A. No
    • B. Yes - Recipient systems can be defined by the school only
    • C. Yes - Recipient systems can be defined by the school or higher (enterprise/departmental) authority and are not able to be modified schools (T1, T2)

    No recommendation yet.

  • PF43Privacy – Functionality

    Can the customer of your service restrict the data elements/fields that are shared with each individual recipient system?

    • A. No
    • B. Yes (please specify) (T1, T2)

    No recommendation yet.

  • PF44Privacy – Functionality

    Does your service have an administrative view that clearly shows to the customer which recipient systems your service is currently sharing customer’s data with and the types of data being shared?

    • A. No
    • B. Yes (T1, T2)

    No recommendation yet.

  • PF45Privacy – Functionality

    Does your service require customers to regularly reauthorize all recipient and integrating systems and perform a review of all data elements/fields shared?

    • A. No
    • B. Yes (please describe the process including frequency) (T1, T2)

    No recommendation yet.

  • PF46Privacy – Functionality

    Does your service offer the ability to filter and thereby prevent, exclude or limit the collection or handling of a specific individual’s information or their related data?

    • A. No
    • B. Yes - filtering can be applied only after source data is consumed by your service. Filtered records are then not shared with recipient systems (please describe)
    • C. Yes - filtering can be applied prior to data being consumed by your service (T1, T2) (please describe)
    • D. Yes – other (please describe)

    No recommendation yet.

  • PF47Privacy – Functionality

    When a customer withdraws data sharing approval for a recipient system what action does your service take?

    • A. The service immediately suspends all data sharing with the recipient system.
    • B. The service notifies the recipient system of the withdrawal of approval.
    • C. The service purges all data within the service it holds related to the recipient system.
    • D. All of the above (T1, T2)
    • E. None of the above.

    No recommendation yet.

  • PF48Privacy – Functionality

    Does your service support the two-way flow of data i.e. data can be sent to a recipient system AND data can be returned from the recipient system to your service for write-back to customer systems?

    • A. No
    • B. Yes. Please specify which systems and data are supported for write-back from your service. (T1, T2)

    No recommendation yet.

  • PF49Privacy – Functionality

    Prior to onboarding a recipient system to your service, what due diligence checks and verifications are performed by your organisation on recipient systems?

    • A. Security check performed or evidence of security maturity obtained (please specify including details of any industry standard or other certifications)
    • B. Privacy check performed or evidence of privacy maturity obtained (please specify including details of any industry standard or other certifications)
    • C. Security and privacy requirements are detailed in contracts between the service’s organisation and the recipient system
    • D. All of the above (T1, T2)
    • E. None of the above.

    No recommendation yet.

  • PF50Privacy – Functionality

    Are ongoing checks and monitoring performed by your organisation on the service’s recipient systems to ensure compliance with security and privacy requirements?

    • A. Yes (please detail and specify frequency) (T1, T2)
    • B. No

    No recommendation yet.

Interoperability

  • DS4Tier AllInteroperability – Data Standards

    Select from the following education specific data standards that are supported by the service for importing or exporting data.

    • A. SIF Australia (AU)
    • B. SIF New Zealand (NZ)
    • C. IMS OneRoster
    • D. Other (please specify)
    • E. None of the above

    Our answerReady

    None

    No SIF, OneRoster, LTI.

  • DS5Tier AllInteroperability – Data Standards

    Has the service undertaken any assurance or compliance testing against any education specific integration technologies or data standards?

    • A. SIF Assurance
    • B. IMS OneRoster conformance certification
    • C. IMS Learning Tools Interoperability (LTI)
    • D. NSIP HITS Testing
    • E. Other (please specify)
    • F. None of the above

    No recommendation yet.

  • DS6Tier AllInteroperability – Data Standards

    After exchanging or consuming data into the product how Collected for reference only soon is this information available to end users of the product? (e.g., if a new set of school master data is imported via an API, is this available immediately in the product drop downs, reports, etc., is the import manually reviewed and available within 5 business days etc.)?

    • A. Immediately
    • B. Other time frame (Please specify)

    No recommendation yet.

  • INT5Tier 1&2Interoperability – Technical Integration

    Please select from the following integrations or connections that are available within the service.

    • A. Native (vendor-provided) integrations
    • B. Marketplace / Partner-built integrations
    • C. Open APIs (e.g. REST, GraphQL etc for custom built integrations)
    • D. FTP/SFTP (e.g. automatically importing or exporting data from a FTP server)
    • E. Data feed (e.g. routinely fetching an XML file from a URL)
    • F. Direct database connection (e.g. SQL user or via an agent software)
    • G. Data standards-based integration (e.g. LISS, SIF)
    • H. Other (please specify)
    • I. None of the above

    Our answerReady

    Google sign-in

    List every native integration.

  • INT6Tier 1&2Interoperability – Technical Integration

    What role types are available to restrict which integrations and connections are available to users within the service?

    • A. School Administrator
    • B. Department / Jurisdiction / District Administrator
    • C. Other (please specify)
    • D. None of the above

    No recommendation yet.

  • INT7CriticalTier 1&2Interoperability – Technical Integration

    In relation to native and partner built connections or integrations, are agreements in place between the organisation and all 3rd party services being connected or integrated with and do these agreements cover: • the purpose for data sharing; • the scope of data to be shared (e.g. academic results); • the scale of data sharing (e.g. current student records only, or a specific year level); • the security and privacy controls in place in recipient systems; and • ownership of data. Furthermore, data agreements are updated to reflect changes in any of the above?

    • A. Yes (please specify) (T1, T2)
    • B. No (#T1, #T2)

    Our answerNeeds document

    A

    Google API terms + developer agreement saved as the agreement.

  • INT8Tier 1&2Interoperability – Technical Integration

    In relation to partner built connections or integrations, what due diligence checks and verifications are performed by your organisation prior to the connection or integration being made available to users?

    • A. Security check performed or evidence of security maturity obtained (please specify including details of any industry standard or other certifications)
    • B. Privacy check performed or evidence of privacy maturity obtained (please specify including details of any industry standard or other certifications)
    • C. Security and privacy requirements are detailed in contracts with the organisation that develops and manages the integration or connection
    • D. All of the above (T1, T2)
    • E. None of the above.

    No recommendation yet.

  • INT9Tier 1&2Interoperability – Technical Integration

    In relation to partner built connections or integrations, does your organisation conduct ongoing monitoring to ensure compliance with your privacy and security requirements (e.g. developer guidelines, platform rules etc).

    • A. Yes (please specify) (T1, T2)
    • B. No

    No recommendation yet.

  • INT10Tier 1&2Interoperability – Technical Integration

    In relation to native and partner built connections or integrations, does your service require the user to re- authorise or reconfirm integrations are still valid on a periodic basis?

    • A. Yes (please specify timeframe) (T1, T2)
    • B. No

    No recommendation yet.

  • INT11Tier 1&2Interoperability – Technical Integration

    In relation to native and partner built connections or integrations, does the service provide privacy controls to restrict a users information (and any related information) from being shared to the integration (e.g. toggle opt-in/opt-out of certain users).

    • A. Yes (please specify) (T1, T2)
    • B. No
    • C. N/A – integration is “consume-only”, returns data to the same user, or transfers no personal data

    No recommendation yet.

  • INT12Interoperability – Technical Integration

    Question retired 2025

    No recommendation yet.

Safety

  • SFP1Tier 1&2

    Does the organisation regularly review and incorporate the Safety by Design principles into the product design and throughout operation of the service?

    • A. Yes (T1, T2)
    • B. No

    Our answerNeeds document

    Yes

    Safety by Design statement mapped to eSafety principles.

  • SC1Tier 1&2

    Is there an acceptable usage policy for the service that is freely available and: - Published on the internet, or - Provided to customers prior to usage of the service?

    • A. Yes - Published on the website (please provide a link) (T1, T2)
    • B. Yes - Provided to users prior to usage of the service (please specify) (T1, T2)
    • C. No

    Our answerNeeds document

    Yes

    Acceptable use policy (draft exists on trust site).

  • SC1ATier 1&2

    If students use or interact with the service, is the acceptable usage policy written in child friendly language?

    • A. No
    • B. Yes (T1, T2)
    • C. N/A - Students do not use or interact with the service

    Our answerNeeds build

    A today

    No child-friendly acceptable-use text on the activity join screen. Write and add.

  • SC1BTier 1&2

    Please provide details on how to access the service's acceptable usage policies, weblinks and any other relevant materials.

    No recommendation yet.

  • SC2Tier 1&2

    Does the organisation (which provides the service) have a process to handle the following from customers: • Technical and operational fault reports • Security incidents and concerns • Privacy complaints and requests; and • Child safety complaints?

    • A. No
    • B. Yes - includes some of the above
    • C. Yes - includes all of the above (T1, T2)

    Our answerNeeds document

    C

    One intake process for faults, security, privacy, complaints, child safety, each with owner and timeframe.

  • SC3CriticalTier 1&2

    Does the organisation have processes in place to identify, respond to, or disclose any known instances of child‑safety‑related misconduct or offences involving its staff or contractors?

    • A. No (#T1, #T2)
    • B. Yes (T1, T2)

    Our answerNeeds document

    B

    Process in the security policy; declaration of no known instances.

  • SC4

    Does the organisation that provides the product or service ensure all of its staff/contractors: • Receive induction regarding the importance of child safety; • Are appropriately supervised to ensure they are behaving in a child safe way when supporting schools; • Receive training that acknowledges student diversity; • Consider diversity (gender-diversity, religious beliefs, indigenous cultural safety, etc) in the product design?

    • A. No
    • 1 &
    • B. Yes - some 2of the above
    • C. Yes - all of the above (T1, T2)

    Our answerNeeds document

    C

    Child-safety induction record; note the cultural-content review step added after the Te Ara Whakamana complaint.

  • SC5Tier 2

    Are controls in place within the service to restrict non- school users from interacting with the school's students except where the user has been individually authorised by the school to do so?

    • A. No
    • B. N/A - There are no student communication features or methods
    • C. Yes - Please specify

    Our answerReady

    B

    No student communication features.

  • SC6

    Does the service have real time detection tools to quarantine and alert administrators to offensive and/or inappropriate comments, messaging and content? For each functionality, select whether this control is available.

    • A. Available
    • B. Not Available Applicable functionality: - Chat / Instant Messaging - Content creation - Commenting / Community Forums

    Our answerNeeds build

    Available for content creation

    Provider moderation + own output checks; describe.

AI Module

  • AI_G1CriticalTier AllAI – General

    Please select if AI is used for any of the use cases or applications as described below (e.g. the ST4S AI Exclusion List): • Processes personal information (e.g. receives student names, gender, racial/ethnic origin or other personal information including sensitive information) • Processes data that may be used to create profiles of individuals or groups that are used to further develop the model or other purposes not within the primary interest of the school • Processing biometrics, human attributes, motions, metrics or attributes whether physical or mental (e.g. facial recognition and scanning, eye tracking, detecting movement, determining or predicting emotions, student disability, learning difficulties etc.) • Student monitoring, behaviour management and observation services • Administrative support and decision making (e.g. automatically vetting enrolment or scholarship applications, complaint handling, disciplinary action etc) • Note taking (e.g., voice recording, speech recognition to-text transcribing, etc) • Utilising NSFW2 AI models, producing or outputting NSFW content or any other content that may be deemed offensive by a reasonable member of the school community •Applications or services which process health and wellbeing data (e.g. physical or mental health, fitness, meditation, food consumption, body metrics etc) • Prohibited uses as defined under the EU AI Act • Any application of AI that may be considered by the ST4S Team, a ST4S Working Group member or a reasonable member of the school community to be: o Invasive o Unethical o Pose a risk to safety, human rights or privacy o Not be within the best interests of the student and/or school • Processing files, media or content that is not manually uploaded by the user but rather provided via an integration or consistent connection to file libraries, directories, file and media hosting services etc (e.g. via API, FTP etc)

    • A. Yes (please specify)
    • B. No

    Our answerNeeds decision

    B, with a sentence per bullet

    No excluded use. Kuraplan Shield (live 15 Sep 2026, opt-in beta) pseudonymises names and contact details before every model call, report comments included. Answer B only once Shield is on by default; today it is A for the 'processes personal information' bullet.

  • AI_G1ACriticalTier AllAI – General

    Are AI features or functions designed to receive or process personal information?

    • A. Yes
    • B. No

    Our answerNeeds decision

    B once Shield is default-on; A today

    Kuraplan Shield is live (PR #774 merged 15 Sep 2026) but opt-in for beta accounts. With it on, the model receives Student_1 style placeholders, never names; verified in production logs and 100 bench runs with 0 leaks. Flip PII_SHIELD to on for all users, then answer B.

  • AI_G1BTier AllAI – General

    Can the AI features and functionalities be disabled by a school or administrator user for all other users?

    • A. Yes
    • B. No
    • C. No, but schools can request this

    Our answerNeeds build

    A

    School policy control plane: AI off per school. Build.

  • AI_G2Tier AllAI – General

    Please select from the following which best describes AI features or functions within the service:

    • A. Automated grading and feedback systems
    • B. AI-driven curriculum design and optimisation
    • C. Anonymised Analytics and Reporting
    • D. Analytics and Reporting with Personal Information
    • E. Educational chat bots
    • F. Non-educational chat bots
    • G. Generation of learning resources and content
    • H. Language processing for plagiarism detection
    • I. AI-assisted research and data analysis tools
    • J. Text translation
    • K. Image, video or audio generation
    • L. Other (please specify)

    Our answerReady

    B, G; A for activity marking

    Curriculum design, resource generation; automated marking of activity answers.

  • AI_G3Tier AllAI – General

    Please describe how the service utilises AI features and Free text field functionality

    Our answerNeeds document

    Free text

    Plain description of planner, generators, chat, marking.

  • AI_G4Tier AllAI – General

    What type of users have access to AI functionality within the service? Select all that apply:

    • A. Students
    • B. Parents
    • C. Teachers
    • D. Admins
    • E. Other (please specify)

    Our answerReady

    A, B, C

    Students (activity helper chat and hints, no account), parents, teachers.

  • AI_G5Tier AllAI – General

    For your products AI solution, select from the following options which best describes the AI solutions or models in use.

    • A. Ready-made AI solution or foundational model from another provider (e.g. OpenAI, Gemini etc) with no changes
    • B. Another provider's AI solution or foundational model with customisations (e.g. to better fit the services needs such as with custom GPTs or extended data sets)
    • C. Utilises an AI solution or foundational model developed internally within your organisation.
    • D. Other (please specify)

    Our answerReady

    A

    Foundation models from Anthropic, OpenAI, Google via Vercel AI Gateway.

  • AI_G5ATier AllAI – General

    Can you describe how your AI model is integrated with or Free text (Must include hyperlink to dependent on the foundation model? And how does it foundation model terms page) contribute to the EdTech’s system functionality?

    Our answerNeeds document

    Free text with gateway link

    Describe AI Gateway routing and ZDR.

  • AI_G5BTier AllAI – General

    Which foundation model 'Terms' apply to you (the Vendor) from the foundation model you used to develop your model? For example, with OpenAI, it can be either 'Plugins and Actions Terms' or 'Business Terms' for non-individual use. Please provide a hyperlink to the applicable terms. If multiple models are in use, please list all terms as they apply.

    • A. Free text (Must include hyperlink to foundation model terms page)

    Our answerNeeds document

    Business/API terms of each provider, linked

    Not consumer terms.

  • AI_G6Tier AllAI – General

    Please list all AI models used by your product and advise Free text field if access is provided via a third party platform e.g. Anthropic Claude via AWS Bedrock

    Our answerNeeds document

    List models + 'via Vercel AI Gateway'

    Model inventory document.

  • AI_G7Tier AllAI – General

    What type of model is the AI solution or model used in A. Generative AI model your application built on? B. Predictive AI model C. Transfer learning model D. Semi-supervised learning model E. Unsupervised learning model F. Reinforcement learning model G. Meta-learning model H. Other (please specify)

    Our answerReady

    Generative AI model

    Informational.

  • AI_G8Tier AllAI – General

    Does the organisation’s current insurance policy cover A. Yes (please specify) incidents and breaches directly related to the B. No deployment or operation of AI technologies, including but not limited to data privacy violations, unintended operational behaviours, or AI system failures? Please provide details on the scope of coverage.

    Our answerDeclare gap

    No today

    Get a quote that covers AI incidents.

  • AI_G9Tier AllAI – General

    What sources of information or data sets does the AI solution consume or interact with? Select all that apply:

    • A. Information or data sets uploaded or entered by an end-user
    • B. Information or data sets created from your organisation's existing information
    • C. Information or data sets created by a third party
    • D. Real-time information or data sets including data feeds
    • E. Other (Please specify)

    Our answerReady

    A, B; no real-time feeds

    User prompts, Kuraplan curriculum content, provider knowledge.

  • AI_H1Tier AllAI – Hosting

    In which countries are the AI solutions or models used in Multi Choice - Country List your product hosted (including inference endpoints and related services)?

    Our answerReady

    United States

    All inference endpoints.

  • AI_H2CriticalTier AllAI – Hosting

    Will end users be informed of any relocation or expansion, such as a change of country, involving the AI model and the infrastructure or services used to host it?

    • A. No
    • B. Yes (specify average notification lead time)

    Our answerNeeds document

    B, 30 days

    Clause in terms.

  • AI_L1Tier AllAI – Logging

    Does the system log user inputs and outputs to the AI model, including the following information: • Date and time of the request or event • User ID associated with the account • Session information • Contents of the request and corresponding output • Error messages or exceptions • Metadata or contextual information

    • A. All of the above
    • B. Some of the above (please specify)
    • C. None of the above

    Our answerReady

    A

    Prompts, outputs, user id, timestamps logged. Confirm errors and metadata fields.

  • A1_L1ATier AllAI – Logging

    How long are these logs retained for and are they deleted or anonymised?

    • A. Logs are deleted after the session is ended by the user (e.g. the user closes the chat with the AI)
    • B. Logs are deleted after a period of time (specify timeframe)
    • C. Logs are anonymised after the session is ended by the user (e.g. the user closes the chat with the AI)
    • D. Logs are anonymised after a period of time (specify timeframe)
    • E. Other (please specify)
    • F. None of the above

    Our answerNeeds build

    B, 90 days

    Implement the purge, then answer.

  • A1_L1BTier AllAI – Logging

    Is there a function within the service to export these logs?

    • A. Yes (please specify)
    • B. No

    Our answerReady

    A

    Export on request; self-service later.

  • AI_L2Tier AllAI – Logging

    Does your organisation enforce logging and monitoring to detect anomalies or malicious activity associated with the AI system. These could be to detect: • any change in behaviour or performance that may indicate a compromise or data drift • ensure compliance obligations are met and to aid investigation and remediation efforts in the event of an incident • Log and monitor the network and endpoints that host your AI system to detect attempts to access, modify or copy system data • sign of automated prompt injection attacks

    • A. Yes
    • B. No

    Our answerNeeds build

    A

    Sentry + usage alerts; add prompt-injection flags.

  • AI_A1Tier AllAI – Access

    Does the solution have controls (i.e. role based access) to restrict access to certain users (e.g. students or teachers) from accessing or interacting with AI features or functionality?

    • A. Yes (please describe)
    • B. No

    Our answerReady

    A

    Planning and generation need a teacher/parent session. Students reach only the activity helper and hints via a teacher's link.

  • AI_HR1CriticalTier AllAI – Human Resources

    Is training and education provided to all persons involved in the design, evaluation, development, and support of AI solutions or models on the following topics: • Ethical AI, covering aspects such as fairness, transparency, and bias mitigation. • User-centric design principles for enhancing usability and user experience. • Compliance awareness, including understanding regulations and legislative requirements relevant to AI implementation. • Privacy best practices and requirements for protecting user data and ensuring compliance with privacy regulations. • Cybersecurity training to mitigate risks and ensure the security of AI systems. • Education on online safety to promote awareness and responsible use of AI technologies.

    • A. All of the above
    • B. Most of the above
    • C. No or only some of the above

    Our answerNeeds document

    B

    Founder completes courses on the six topics; keep certificates.

  • AI_T1CriticalTier AllAI – Technical and Testing Controls

    Does your organisation have a responsible AI framework and ethics policy which includes at a minimum: 1. Governance: • Principles and Values: Establish clear principles like fairness, transparency, and accountability that guide AI development and use. • Roles and Responsibilities: Define roles and responsibilities for all stakeholders involved in the AI lifecycle, from developers to users. • Risk Management: Implement processes to identify, assess, and mitigate potential risks associated with AI systems, including bias, security vulnerabilities, and societal impact. 2. Design and Development: • Human-Centered Design: Focus on designing AI systems that meet human needs, prioritize well- being, and are inclusive. • Data Management: Ensure responsible data collection, storage, and usage practices that respect privacy regulations and minimize bias. • Algorithmic Transparency and Explainability: Promote transparency in how AI systems make decisions, allowing users to understand the reasoning behind outputs. 3. Testing and Deployment: • Testing and Validation: Implement rigorous testing procedures to ensure AI systems perform as expected, are reliable, and avoid unintended consequences. • Monitoring and Auditing: Continuously monitor deployed AI systems to identify potential issues, biases, or performance degradation. • Human Oversight: Maintain human oversight throughout the AI lifecycle for responsible decision-making and intervention when necessary. 4. Communication and Stakeholder Engagement: • Transparency with Users: Clearly communicate how AI systems work, their limitations, and how user data is used. • Stakeholder Engagement: Engage stakeholders like policymakers, regulators, and the public in discussions about responsible AI development and deployment. 5. Accountability and Continual Improvement: • Accountability Mechanisms: Establish clear accountability for potential harms caused by AI systems. • Continual Learning and Improvement: Continuously learn from data, feedback, and real- world deployment to improve AI systems and address emerging issues.

    • A. Yes (please specify)
    • B. No

    Our answerNeeds document

    A

    Responsible AI framework document following the five headings.

  • AI_T2CriticalTier AllAI – Technical and Testing Controls

    Does your organisation conduct security testing and assessments of AI systems and their features/functionality, which encompass the following key areas: • Penetration and jailbreak testing • Vulnerability scanning • Testing of access control mechanisms

    • A. Yes (Please specify the frequency and timeframe)
    • B. No

    Our answerNeeds build

    A, quarterly

    Jailbreak/prompt-injection suite (promptfoo or garak) run quarterly, reports kept.

  • AI_T3CriticalTier AllAI – Technical and Testing Controls

    Does your organisation conduct privacy testing and A. No assessments of AI systems and their B. Yes (every 6 months or less) features/functionality, which encompass the following C. Yes (between every 6 - 12 months) key areas: D. Yes (more than every 12 months) • Data minimization testing • Data anonymization testing • User control testing • Compliance testing (Please specify the frequency and timeframe)

    Our answerNeeds build

    B, every 6 months or less

    PII-leak tests in CI with planted names; count as continuous.

  • AI_T4CriticalTier AllAI – Technical and Testing Controls

    Does your organisation conduct safety testing and assessments of AI systems and their features/functionality, which encompass the following key areas: • Bias and fairness analysis • Explainability verification • Edge case validation • Content and interaction integrity checks • Testing for inappropriate content creation, responses or other harmful1 interactions

    • A. Yes (Please specify the frequency and timeframe)
    • B. No

    Our answerNeeds build

    A, quarterly

    Bias and content-integrity eval set across year levels and cultures.

  • AI_T5CriticalTier AllAI – Technical and Testing Controls

    Does your organisation implement the guidance of the OWASP Machine Learning Security Top 10 or equivalent? Reference Link: https://owasp.org/www-project-machine-learning- security-top-10/

    • A. Yes - All guidance is implemented
    • B. Yes - Most of the guidance is implemented
    • C. None or only some of the guidance is implemented

    Our answerNeeds document

    B

    Two-column mapping of ML Top 10 to what we do or why N/A.

  • AI_T6CriticalTier AllAI – Technical and Testing Controls

    Does the organisation implement the guidance from the OWASP AI Security and Privacy Guide (or equivalent guidance)? Reference: https://owaspai.org/

    • A. Yes - all of the guidance is followed
    • B. Yes - some of the guidance is followed
    • C. No

    Our answerNeeds document

    B

    Same mapping for the OWASP AI Security and Privacy Guide.

  • AI_T7CriticalTier AllAI – Technical and Testing Controls

    Are there controls in place during the release of updates to AI systems, features/functions and models which include: • Transparent documentation to end users on how the AI functions, limitations, what is it sourcing data from etc • Clearly identifying and warning users of new AI systems, models and features/functions etc • Allowing users to opt-in and opt-out of new AI systems, models, features/functions etc • AI models are clearly versioned and this is communicated to end users • Users understand the limitations of the models use (e.g. disclaimer notices) • A published history of change logs for end users to observe and inspect changes to the AI that may differ from its previous use • Users are notified when changes to AI systems, models and features/functions occur.

    • A. Yes - All of the above
    • B. Yes - Most of the above
    • C. No or only some of the above

    Our answerNeeds build

    B

    Public /ai page + changelog + notice on model swaps; opt-out per feature is the gap.

  • AI_T8CriticalTier AllAI – Technical and Testing Controls

    If information is collected from users for training or developing AI/ML models, what processes are in place to verify information is complete, accurate and suitable to be incorporated into training?

    • A. No processes are in place to verify information or it is not completed routinely
    • B. Information is verified manually for training per a standard process
    • C. Information is automatically verified (e.g. using another AI model to verify information for quality and assurance)
    • D. A combination of manual human and automatic verification processes are followed
    • E. Other (please specify)
    • F. N/A - Information is not collected from users for training or developing AI/ML models

    Our answerReady

    F

    No user data collected for training.

  • AI_T9CriticalTier AllAI – Technical and Testing Controls

    Is there a full and complete record of the training data you have supplied, and the processes and artefacts involved in the production/development/fine-tuning of the AI model?

    • A. Yes
    • B. No

    Our answerReady

    A with explanation

    No fine-tuning; prompt templates and eval sets are versioned in git.

  • AI_T10CriticalTier AllAI – Technical and Testing Controls

    Is personal information used throughout the testing and development lifecycle of features, functions or models of the AI solution? (e.g. when testing AI features or functions, executing test cases etc)

    • A. Personal information is deidentified, and consent has been obtained
    • B. Personal information is deidentified, and consent has not been obtained
    • C. Personal information is not deidentified, and consent has been obtained
    • D. Personal information is not deidentified, and consent has not been obtained
    • E. Personal information is not used throughout the testing and development lifecycle

    Our answerNeeds build

    E

    Synthetic and de-identified test data only; dev project rule.

  • AI_T11Tier AllAI – Technical and Testing Controls

    During the AI model's testing and training lifecycle, do you engage external auditors to verify that the outputs are minimally affected by misinformation and bias?

    • A. Yes (please specify)
    • B. No

    Our answerReady

    B

    No external audit yet; optional.

  • AI_I1Tier AllAI – Incidents

    Have any of the AI systems, features, functions and models been involved in any of the following: • A security incident or breach • A privacy incident or breach • Producing biased results • Producing harmful1 or inappropriate content such as: o NSFW or adult content o Deepfakes o Harmful responses such as explicit descriptions of suicide or self-harm methods o Other content or responses that may be deemed offensive or harmful to young people or a reasonable member of the school community.

    • A. No (T1, T2)
    • B. Yes – less than 12 months ago (please specify) C. Yes – greater than 12 months ago (T1, T2) (please specify)

    Our answerReady

    A

    No AI incidents in 12 months.

  • AI_I2CriticalTier AllAI – Incidents

    Does your organisation have a documented process for identifying, investigating, and reporting on AI incidents, including those related to security incidents/breaches, privacy breaches/incidents, bias, or harmful content generation?

    • A. Yes
    • B. No

    Our answerNeeds document

    A

    AI section in the incident response plan.

  • AI_D1Tier AllAI – Data Deletion and Retention

    If a user withdraws consent of their data being included in the AI solution or model is the user data deleted and the model retrained?

    • A. User data is deleted and the model is retrained
    • B. User data is deleted and the model is not retrained
    • C. User data is never used to train the AI model

    Our answerReady

    C

    Never trained on user data.

  • AI_D1ATier AllAI – Data Deletion and Retention

    How long after deletion is the model retrained?

    • A. retrained within 3 months
    • B. retrained within 6 months
    • C. retrained within 12 months
    • D. retrained after 12 months or longer

    No recommendation yet.

  • AI_GO1CriticalTier AllAI – Governance

    Does the organisation designate a dedicated role, distinct from development and product ownership, responsible for AI safety (e.g. AI Officer, AI Safety Officer or Ethics etc), and does this role include the following responsibilities: • Risk identification and assessment of AI systems. • Developing safety guidelines and mitigations for AI development and use. • Staying up-to-date on AI safety research and best practices. • Monitoring and auditing AI systems after deployment. • Advocacy and communication regarding responsible AI development. • Data governance. • Handling feedback and complaints (e.g. feedback from end users)

    • A. Yes, with all the specified responsibilities
    • B. Yes, with most of the specified responsibilities
    • C. No or only some of the specified responsibilities

    Our answerNeeds decision

    B

    Name an external adviser or teacher-advisory member with a signed role description.

  • AI_GO2Tier AllAI – Governance

    In the context of AI: with regards to any third-party providers that make up the solution, or provide service to you, does your organisation: • have an inventory of all third-party service providers; • regularly assess and manage the risks associated with these third-party providers; and • ensure contractual agreements require third- party providers to comply with information security, privacy policies, and regulatory obligations.

    • A. Yes (please specify)
    • B. No

    Our answerNeeds document

    A

    Provider register with risk notes and DPA/business terms.

  • AI_PA1Tier AllAI – Privacy

    Is data entered into the model also saved for training purposes or is it discarded? (e.g. Are all inputs of a student discarded or are inputs also saved into the model to retrain and improve?) B. Inputs are retained for the purposes of C. Inputs are discarded D. Other (please describe)

    • A. Inputs are retained for the purposes of retraining and model development - By Default retraining and model development - If Opted In

    Our answerReady

    Inputs are discarded

    ZDR at the gateway; providers under no-training business terms.

  • AI_PA2CriticalTier AllAI – Privacy

    If the AI solutions or models are trained across user data (including where de-identified, content and media created etc) is explicit consent obtained from the user?

    • A. Yes (please specify how consent is obtained from the user)
    • B. No
    • C. Not applicable - user data is not used for training purposes

    Our answerReady

    C

    Not trained on user data.

  • AI_PR1CriticalTier AllAI – Privacy General and Terms

    Are users opted-out by default of having user data and Rows: any other related information (including where de- identified, aggregated, etc.) being provided to AI?

    • A. Used for AI Usage Analytics
    • B. Stored for Personalization by the AI
    • C. Used for Training, Developing and Improving AI Models Options: • Opt-Out by Default • Opt-in by default • Not Applicable

    Our answerNeeds build

    Opt-out by default on all three

    Teacher Memory personalisation must default off with a visible setting.

  • AI_PR2CriticalTier AllAI – Privacy General and Terms

    Does the service offer users control over their data with easily accessible privacy settings to manage consent and preferences on how user data is to be used with AI systems, models and features/functionality (including for model training purposes)?

    • A. Yes (please specify)
    • B. No
    • C. Not applicable - user data is not used with AI systems, models, features/functionality, or for training purposes

    Our answerNeeds build

    A

    AI settings page: personalisation, history, turn AI off.

  • AI_PR3CriticalTier AllAI – Privacy General and Terms

    Is there an easily accessible statement (Privacy Policy, Privacy Statement, Privacy Notice, Data Protection Policy, User/Customer Data Policy, etc) that informs individuals about the use and collection of their personal information or any other related data (e.g. including where de-identified, aggregated or otherwise) for use in AI (ML, LM, LLM) and does the statement outline the following in a clear and transparent manner: • what personal data will be collected • the purposes for processing personal data • the retention periods for personal data • who the data is shared with • the individual's right to access, rectify or stop the use of their personal data • how to withdraw consent, Additionally, is this information provided in a reasonable timeframe, such as before an individual registers or their information is disclosed to AI systems and models?

    • A. Yes (please specify)
    • B. No

    Our answerNeeds document

    A

    AI section of the privacy policy + first-run notice.

  • AI_PR4CriticalTier AllAI – Privacy General and Terms

    Has your organisation established a consent management process to manage user consent for their information being used for AI purposes, including providing and withdrawing consent?

    • A. No
    • B. Yes (please specify) (T1, T2)
    • C. Not applicable - user data is not used with AI systems, models, features/functionality, or for training purposes

    Our answerNeeds build

    B

    Consent stored per user; withdraw in settings.

  • AI_PR5Tier AllAI – Privacy General and Terms

    Do you regularly review your processing, documentation and privacy information to check that your purposes have not evolved over time beyond those you originally specified? (e.g. function creep)

    • A. Yes - On a quarterly or more frequent basis (specify timeframe)
    • B. Yes - Less frequently (specify timeframe)
    • C. No

    Our answerNeeds document

    A, quarterly

    Dated review of AI processing purposes.

  • AI_PR6CriticalTier AllAI – Privacy General and Terms

    Can users adjust settings to prevent information, including prompts shared with the AI models, from being shared with third parties?

    • A. Yes (please specify)
    • B. No
    • C. N/A - Information and prompts are not shared with third parties

    Our answerNeeds build

    A

    Setting that disables AI features entirely (stops prompts reaching providers).

  • AI_PR7AI – Privacy General and Terms

    Does the vendor indemnify the jurisdiction and users (e.g. staff, teachers and students) in respect of copyright or moral rights infringements that occur in connection with the use of the AI system, and if so, are there any caps or limitations on those indemnities?

    • A. Yes (please specify)
    • B. No

    Our answerNeeds decision

    B, or A with a cap

    Copyright indemnity is a legal decision. Most small vendors answer B.

  • AI_PR8AI – Privacy General and Terms

    Does the vendor give warranties that the use of the AI model or system will not infringe copyright or moral rights, and if so, are there any caps or limitations on those warranties?

    • A. Yes (please specify)
    • B. No

    Our answerNeeds decision

    B, or A with a cap

    Same.

  • AI_PF1CriticalTier AllAI – Product Functionality

    Do users receive a notification or a disclosure notice informing them when they are engaging with an AI system or when the content they are interacting with has been generated by an AI system? E.G> Chat bots clearly identify themselves as being an AI chat bot, charts and graphs produced by an AI system are clearly labelled as being AI generated.

    • A. Yes (please specify)
    • B. No

    Our answerNeeds build

    A

    'AI-generated' label on every output and in the UI.

  • AI_PF1ACriticalTier AllAI – Product Functionality

    Does the notification or disclosure notice include disclaimers indicating that the AI system may produce responses or outputs that could be inaccurate and contain biases?

    • A. Yes (T1, T2)
    • B. No

    Our answerNeeds build

    A

    Disclaimer text: may be inaccurate or biased.

  • AI_PF2Tier AllAI – Product Functionality

    What type of content can be generated or outputted by the AI systems or models?

    • A. Images
    • B. Videos
    • C. Text e.g. blog posts, social media posts, newsletters, presentations
    • D. Audio or music
    • E. Quizzes
    • F. Emails
    • G. Infographics
    • H. Code, scripts or other web development content
    • I. Other (please specify)

    Our answerReady

    A, C, E; also slides, worksheets

    Images, text, quizzes.

  • AI_PF3Tier AllAI – Product Functionality

    Can users input their own content, media or other assets in to be modified or edited using AI tools/functionality? (e.g. not using text prompts to output images but building upon already existing images)

    • A. Yes (please specify)
    • B. No

    Our answerReady

    A

    Teachers can paste their own material to adapt.

  • AI_PF4CriticalTier AllAI – Product Functionality

    Within the service, are there easily accessible tools for users to provide feedback on AI features, such as: • Commenting on the accuracy of a response or output of the AI (e.g., thumbs up/down) • Reporting harmful1 or inappropriate content (e.g., biased outputs, harmful digital communications, misinformation) • Providing general feedback in relation to a particular AI feature • Additionally, can users provide other relevant feedback to improve the AI's performance?

    • A. Yes (please specify)
    • B. No

    Our answerNeeds build

    A

    Thumbs up/down on outputs: build.

  • AI_PF5CriticalTier AllAI – Product Functionality

    What methods are enabled for users to report AI- generated content that may be harmful or breaches the terms of service?

    • A. Form
    • B. Direct email to the service provider
    • C. Chat
    • D. Other (please specify)
    • E. None of the above

    Our answerNeeds build

    A, B

    Report button (form) + security@ email.

  • AI_PF6Tier AllAI – Product Functionality

    How does the service provider handle reported content Free text field during the investigation process? (e.g., is it removed from user view, taken down from the public site, etc.) Please specify the timeframes for investigating and taking action (e.g., censoring or removing content, etc.)

    Our answerNeeds document

    Reviewed within 2 business days; removed if inappropriate

    Write the handling procedure.

  • AI_PF7Tier AllAI – Product Functionality

    Are users able to disable AI chat or prompt history?

    • A. Yes - All user types (please describe)
    • B. Yes - But only user types with certain access privileges, i.e., administrative access (please describe)
    • C. No
    • D. N/A - No prompt or chat history is available

    Our answerNeeds build

    A

    Users can delete conversations; confirm 'disable history' exists or build it.

  • AI_PF8CriticalTier AllAI – Product Functionality

    Are there controls to warn, restrict or prevent personal information from being disclosed to the AI model? Select all that apply:

    • A. Automatic safeguards block users from inputting personal information.
    • B. Intermediary filtering systems are in place to remove personal information before it reaches the AI model
    • C. Manual review processes are established to check and prevent personal information disclosure.
    • D. Warnings or prompts remind users not to share personal information
    • E. Other (please specify)
    • F. No controls are available

    Our answerNeeds decision

    B (and D once the prompt-box warning ships)

    Intermediary filter is live in production as Kuraplan Shield: local detector (no model), placeholder swap on every model call including tool results and RAG context, restore on the way back. Opt-in today; select B without caveat once default-on. Warning chip under prompt boxes not built yet.

  • AI_PF8ATier AllAI – Product Functionality

    Please further describe the controls in place to warn, Free text field restrict or prevent personal information from being disclosed to the AI model.

    Our answerReady

    Kuraplan Shield sits between the application and every AI model call. Before a request leaves Kuraplan, a local detector (no AI model involved) finds people's names, email addresses, phone numbers, street addresses, dates of birth and student identifiers in the prompt, the conversation history, retrieved context and tool results, and replaces each with a stable placeholder (Student_1, Student_1_Surname, [email_1]). Names supplied through structured fields such as report-comment rosters are always redacted. The model answers using the placeholders; Kuraplan restores the real values in the reply, including in streamed output. The mapping lives only in memory for the life of the request and is never logged or stored. Coverage is verified by 87 unit tests and a recurring evaluation against production models that inspects the exact request sent to the provider (100 runs, 0 leaks). All model calls also request zero data retention and no training on user data.

    Written from the shipped mechanism (apps/api/src/lib/ai/pii/README.md, evidence pack 07-ai). Add the sentence 'enabled for all users by default' only after the global flip.

  • AI_PF9CriticalTier AllAI – Product Functionality

    Does your organisation provide consumers (end-users) with guidance on: • Understanding how the AI system works • Using the AI system effectively for desired outcomes • Using the AI system responsibly and safely. • Identifying and addressing biases and addressing ethical issues to ensure safe and responsible usage • Protecting user privacy and obtaining consent. • Complying with regulations and legal obligations where applicable • How to provide feedback, report errors and concerns

    • A. All of the above
    • B. Most of the above
    • C. None or only some of the above

    Our answerNeeds document

    B

    Help-centre articles on the seven bullets.

  • AI_SF1Tier AllAI – Safety

    Does your organisation publish help material on how to safely utilise AI functions and features within the service that is: • Easily accessible to the student or young person (e.g. an easy to find help button in the chat bot or on the application), and • Written in child friendly language

    • A. Yes (please specify)
    • B. No

    Our answerNeeds document

    B today

    No child-friendly help on the activity player. Write it: how the helper works, what it won't do, how to report.

  • AI_SF2Tier AllAI – Safety

    Does the organisation consider and apply Safety by Design principles within the AI components of the service?

    • A. Yes (please describe)
    • B. No

    Our answerNeeds document

    A

    Safety by Design statement covering AI.

  • AI_SF2ATier AllAI – Safety

    Please describe Free Text

    No recommendation yet.

  • AI_SF3Tier AllAI – Safety

    Does the organisation incorporate appropriate safeguards to reduce and mitigate the potential misuse of AI features and functionality?

    • A. Yes (please describe)
    • B. No

    Our answerReady

    A. Layered controls, verified 15 Sep 2026: (1) edge rate limits per IP on the API (50 req/30 s anonymous, 300 req/30 s signed in) and bot verification (Vercel BotID) on the two AI endpoints anonymous visitors can reach, chat streaming and quick ideas; (2) a per-account spend meter on every AI call with hard caps by plan (trial US$1.50, Pro and school US$4 per period, school-adjustable), enforced since 2 September 2026 with Slack alerts, and weekly credit limits on free accounts (5 resources, 50 chat turns); (3) provider-side content moderation on model and image outputs, and our own output checks on generated resources; (4) every model call goes through one gateway with zero data retention, and Kuraplan Shield pseudonymises personal information before it leaves; (5) Sentry error tracking and daily chat-sentiment review surface misuse patterns; (6) student-facing AI surfaces are limited to the activity helper and hints, with topic restrictions in the system prompt and no free-form student accounts.

    Every item above is live and evidenced (firewall config, usageCaps.ts, botId middleware, ai_usage metadata). Do not claim prompt-injection filtering or a crisis protocol; those are separate open items (AI_SF6A, AI_SF8).

  • AI_SF3ATier AllAI – Safety

    Please describe Free Text

    No recommendation yet.

  • AI_SF4CriticalTier AllAI – Safety

    Do you have a process in place to recognise and filter out and remove illegal, harmful1 or inappropriate content from AI models or their outputs? (Illegal or harmful content, such as CSEA material, image based abuse (IBA), harmful digital communications and abuse, or false, biased, harmful1, or misleading information, or other unlawful material).

    • A. Yes (please describe)
    • B. No

    Our answerNeeds build

    A

    Provider moderation + own output classifier + removal path.

  • AI_SF4ATier AllAI – Safety

    Please describe Free Text

    No recommendation yet.

  • AI_SF5CriticalAI – Safety

    If students have access to the AI tool and are able to generate their own content does the service have real time detection tools to quarantine and alert administrators to inputs to the AI model which may be: • offensive and/or inappropriate • relating to self-harm or suicide • relating to drugs, alcohol or illicit substances • abuse including sexual abuse, physical or mental • unlawful activity

    • A. Yes - The user is alerted first and then asked if they would like to continue with the prompt as it will notify the school. Opportunity to withdraw the prompt.
    • B. Yes - Alerts to the account holder immediately without warning to the student
    • C. Other (please specify)
    • D. No

    Our answerNeeds decision

    D today

    Students can prompt the activity helper and there is no real-time detection or school alerting yet. Either build it (option A) or disable student chat and hints until it exists.

  • AI_SF6CriticalTier AllAI – Safety

    Are prompts filtered by default before being disclosed to the AI model to minimise or restrict harmful prompts, model manipulation or jailbreaking attempts?

    • A. Yes (please specify)
    • B. No
    • C. Not applicable - users cannot input content or prompts

    Our answerNeeds decision

    A once Shield is default-on (PII only today)

    'By default' is the test. Shield filters PII but is opt-in; prompt-injection and jailbreak filtering not built. Flip Shield on for all users, then answer A and describe PII filtering honestly without claiming injection defences.

  • AI_SF6ATier AllAI – Safety

    What type of content is flagged by the filter? Select all that apply:

    • A. Personally Identifiable Information (PII)
    • B. Data Poisoning attacks
    • C. Prompt injection
    • D. Training attack
    • E. Other (please specify)

    Our answerNeeds decision

    A

    PII is filtered by Kuraplan Shield. Select C (prompt injection) only if that filter gets built.

  • AI_SF7AI – Safety

    Can school administrators enable chatbot message or session limits for their users?

    • A. Yes - please specify
    • B. No

    Our answerNeeds build

    B today

    Per-response and per-IP rate limits exist, but no school-admin control. School policy control plane: build.

  • AI_SF8AI – Safety

    For any interactive AI feature (including chat, messaging, image or other media generation), does the service have a documented and implemented crisis response protocol that includes the following safeguards: 1. Crisis messaging and support signposting / On detection of high risk self harm or suicide content, the AI: • clearly states it cannot help with self harm or D. Not applicable, the service does not provide suicide requests interactive AI features to students or young • avoids providing methods, plans or instructions people. • presents clear, compassionate crisis messaging and prominently displays appropriate emergency and crisis support contacts for the user's country or school or tenant region, for example 000 and Lifeline 13 11 14 in Australia or local equivalents. 2. Crisis safe mode and content restriction / On high risk detection the AI moves into a restricted crisis safe mode that: • refuses or redirects further high risk prompts • limits responses to pre approved, clinically reviewed crisis safe scripts • maintains this state for a defined period, for example at least 30 minutes, rather than resuming normal conversation immediately. 3. AI disclosure and dependency mitigation \ The service helps prevent unhealthy reliance on the AI by: • clearly disclosing at the start of use, and at regular intervals, that the user is interacting with AI and not a human • issuing additional notifications or breaks after extended continuous use, for example at or before three hours of ongoing companion style use, and complying with any stricter local legal requirements. 4. Escalation and notification in education settings \ For school managed accounts, where permitted by law and school policy, high risk events such as explicit suicidal intent or concrete self harm plans: • are flagged as a high priority alert to authorised wellbeing or safeguarding staff only • are covered by a documented workflow that aims for human review and triage within 15 minutes of the alert, with clear roles, privacy safeguards and record keeping. 5. Clinical review and ongoing evaluation \ The crisis response protocol, prompts and AI behaviour: • are co designed or reviewed with qualified mental health professionals, with attention to youth specific guidance where relevant • are tested at least annually, and after any serious incident, using self harm and suicide test cases, with results used to improve detection, refusal and referral behaviour. 6. Other safeguards \ Other safeguards that reduce the risk of harm from self harm or suicide interactions with the AI (please describe).

    • A. Yes, all safeguards are implemented and operating as described.
    • B. Partially, some safeguards are implemented (please specify which).
    • C. No, a crisis response protocol for self harm and suicide is not implemented.

    Our answerNeeds decision

    C today

    Student helper chat is an interactive AI feature with no crisis protocol. Build the protocol (signposting, safe mode, school escalation) or disable student chat until it exists.

  • AI_EV1AI – Evidence

    Organisation's AI Ethics Policy and Responsible AI Framework AI_T1

    No recommendation yet.

  • AI_EV2AAI – Evidence

    Security Testing (e.g. jail breaking / penetration testing) AI_T2, AI_T3, AI_T4

    No recommendation yet.

  • AI_EV2BAI – Evidence

    Privacy Testing (e.g. testing for personal information, warnings and detection tools)

    No recommendation yet.

  • AI_EV2CAI – Evidence

    Safety Testing (e.g. outputs of generated content is appropriate for audiences, checking for dangerous responses, NSFW content etc)

    No recommendation yet.

  • AI_EV3AI – Evidence

    AI Incident Management Plan (for handlining security incidents/breaches, privacy breaches/incidents, bias reports AI_I2 harmful1 content generation)

    No recommendation yet.

  • AI_EV4AI – Evidence

    Would you like to submit additional evidence? AI_EV4 Additional evidence can support us in understanding your AI systems, models and features/functionality. Examples of additional evidence might include: • Publications by your organisation on how models are developed and trained • High level system architecture and networking diagrams

    No recommendation yet.

  • AI_EV5AI – Evidence

    Evidence of external auditors review on the AI model AI_T11

    No recommendation yet.

Desktop and Mobile Applications, Browser Extensions

  • AP0Tier 1&2

    Please select if any of the following application types are available

    • A. Mobile Application (e.g. Phone or Tablet App)
    • B. Browser Extension/Plugin
    • C. Desktop Application
    • D. Other (please specify)
    • E. None of the above

    Our answerNeeds decision

    E. None of the above

    Kuraplan is a web application only (app.kuraplan.com). No mobile app, browser extension or desktop application. NCEA Coach (ChatNCEA), a separate Kuraplan product for students delivered as a native iOS app, is outside the scope of this assessment but shares the Supabase project; disclose that in the scope declaration (00-scope/2026-09-15-scope-declaration.md) and decide whether to move its tables to their own project before submission.

  • AP1CriticalTier 1&2

    Does your organisation conduct a vulnerability scan on all of the service's application types: • Upon each deployment (e.g. when publishing a new version), and • Periodically on a monthly or more frequent basis.

    • A. No (#T1, #T2)
    • B. Yes - meets all of the requirements above but conducted less frequently (T2)
    • C. Yes - meets all requirements above (T1, T2)

    No recommendation yet.

  • AP2CriticalTier 1&2

    Is the mobile app, browser extension and/or desktop application assessed per a security testing methodology that is consistent with the guidance provided by the latest industry standard frameworks (e.g. for Mobile Applications, the OWASP Mobile Application Security C. No (#T1, #T2) Testing Guide)?

    • A. Yes - security testing fully satisfies the guidance provided in an industry standard framework (please specify framework) (T1, T2)
    • B. Yes - security testing partially satisfies the guidance provided in an industry standard framework (please specify framework)

    Our answerReady

    Not applicable

    No mobile app, extension or desktop application exists.

  • MA1Tier 1&2

    Please select from the following channels the mobile A. Apple App Store app offered by your organisation. B. Google Play Store C. Other Android marketplace (please specify) D. Manual installation (please specify) E. Other (please specify)

    Our answerReady

    Not applicable

    No mobile app.

  • MA1ATier 1&2

    Apple App Store URL, Google Play Store URL, Other Android marketplace URL

    Our answerReady

    Not applicable

    No mobile app.

  • MA2Tier 1&2

    Select the device permissions that may be requested by A. Camera the mobile app. B. Photo / Media Library C. Calendar D. Reminders E. Microphone F. Location G. Local Network H. Bluetooth I. Notification J. Health and Motion Data or Activity (e.g. Apple Health Kit, Google Health, Samsung Health) K. No device permissions are requested L. Other (please specify)

    Our answerReady

    Not applicable

    No mobile app.

  • MA3Tier 1&2

    Does the mobile app only request permissions that are A. Yes (T1, T2) necessary for the app to function for its expected B. No purpose?

    Our answerReady

    Not applicable

    No mobile app.

  • BE1Tier 1&2

    Select from the following channels the browser A. Apple App Store or Safari Extension Store extension offered by your organisation: B. Mozilla Firefox Extension Store C. Google Chrome Extension Store D. Microsoft Edge Add-ons Store E. Manual installation or installation outside of an extension store or marketplace (please specify) F. Other (please specify)

    Our answerReady

    Not applicable

    No browser extension.

  • BE2Tier 1&2

    Select the browser/device permissions that are A. Location requested by the browser extension. B. Camera C. Microphone D. Motion sensors E. Bookmarks F. Browser history G. Browser tabs H. Clipboard I. Browser settings J. Read or change site data K. Other (please specify) L. No browser/device permissions are requested

    No recommendation yet.

  • BE3Tier 1&2

    Does the browser extension only request permissions A. Yes (T1, T2) that are necessary for it to function for its expected B. No purpose? 6.8 Evidence Depending on supplier responses to prior questions, the following documentary evidence is required to be uploaded (system accepts PDF, .DOC, .DOCX). Evidence requirements for the AI Module is listed separately within the AI Module section of this guide. # Evidence Related to question ID

    No recommendation yet.

  • EV1

    Attestation of PCI-DSS Compliance CC2

    No recommendation yet.

  • EV2

    ISO27001 Certificate of Compliance / Statement of applicability CC1

    No recommendation yet.

  • EV3

    SOC 2 Type II Certification CC1

    No recommendation yet.

  • EV4

    FEDRAMP (NIST) Certification CC1

    No recommendation yet.

  • EV5

    IRAP Accreditation CC1

    No recommendation yet.

  • EV6

    Your organisation’s Information Security Policy Q7

    No recommendation yet.

  • EV7

    Business Continuity Plan for the service Q2

    No recommendation yet.

  • EV8

    Disaster Recovery Plan for the service Q2

    No recommendation yet.

  • EV9

    Incident Response Plan or Security Incident Management Plan T6

    No recommendation yet.

  • EV10

    Most recent penetration testing report (redacted) for the service T1

    No recommendation yet.

  • EV11

    Most recent vulnerability assessment reports (redacted) for the service T1

    No recommendation yet.

  • EV12

    Patch management standards / process T3, T4, T5

    No recommendation yet.

  • EV13

    Your organisation’s Secure Software Development Lifecycle process Q5

    No recommendation yet.

  • EV14

    Privacy compliance/certification CC1

    No recommendation yet.

  • EV15

    CSA Star CC1

    No recommendation yet.

  • EV16

    HECVAT CC1

    No recommendation yet.

  • EV17

    Sample agreement between service (data integrator, aggregator, data broker, data hub, data distribution hub) and third party PF33

    No recommendation yet.

  • EV18

    A list of all third-party services (company and service names) for which service accounts are required to be created (including access levels e.g., A16A administrator, regular user)

    No recommendation yet.

  • EV19

    Please supply a list of all third-party recipient services (company and service names) including the data types shared (e.g., personal information, PF32 medical information, financial data), and the purpose for sharing, with whom the service currently shares data.

    No recommendation yet.

  • EV20

    Evidence of WCAG compliance for the service. P14

    No recommendation yet.

  • EV21

    1EdTech TrustEd Apps(TM) Certification CC1 In addition, other evidence may be requested or inspected throughout the assessment process. This includes information on a supplier’s website, terms and conditions, privacy policies and other documentation or information. In assessing and reviewing documentation requirements, the ST4S Team makes considerations to: • Content: Does the document contain the sections per the relevant ST4S control as described in the table above. Documentation should contain specific and relevant technical information to the service being assessed. • Quality: Does the document demonstrate a level of standard relevant to the determined tier of the service. Documentation Requirements: All documentation provided throughout the assessment must be in English, be an authorised and final copy by the organisation and contain the organisation’s name and company number. If the supplier holds a valid ISO27001 certification or has undertaken a Soc2Type2 Audit, the ST4S Team may upon review, choose to accept this certificate as meeting some evidence and documentation requirements. Please ensure the relevant certification has been selected within the assessment questionnaire and that you upload the certificate or audit report. Importantly, ISO27001 and Soc2Type2 are only accepted where the supplier’s organisation is named on the certificate and their service was in scope of the review. Verification and Validation: The ST4S Team may contact the author, certifying body etc to verify the authenticity of documentation, evidence, and other information. For example, we may contact the ISO accrediting body to verify an ISO certificate, ask a pen tester to provide evidence of their certification (e.g. providing a certificate number for us to verify) etc. 6.9 Artificial Intelligence (AI Module) A hash (#) indicates a control is critical for compliance, or if not complied with will result in a high risk outcome for the criteria and the overall outcome on the report.

    No recommendation yet.