How EduSwap approaches infrastructure security and data protection
1. Overview
EduSwap Pty Ltd is committed to operating a secure, resilient and privacy-conscious platform for Australian schools.
This Statement outlines the technical, hosting, security and operational controls used to help protect school data and support reliable service delivery.
EduSwap is not intended to store student data and is designed for authorised school staff use.
This Statement should be read together with EduSwap’s Privacy Policy, Data Retention and Deletion Policy, Terms of Service and related platform policies.
2. System architecture overview
EduSwap is designed as a cloud-hosted, multi-tenant SaaS platform for school-to-school equipment exchange.
Its architecture is intended to include a secure web application layer, controlled API access, application services, segregated data handling and encrypted communication between core components.
Permission boundaries are designed to restrict access between schools and support tenant-aware data separation.
A higher-level architecture overview is provided in the EduSwap Architecture page.
3. Hosting environment
EduSwap is intended to operate within Australian-based cloud infrastructure to support privacy, data localisation and school-sector expectations.
Hosting may use major Australian-region cloud infrastructure such as AWS Sydney or Azure Australia East or South East, depending on deployment requirements.
Production data is intended to remain stored within Australia, with no deliberate offshore replication for core platform data.
Where third-party services are used, they are selected with security, privacy and operational suitability in mind.
4. Data security controls
Data in transit is intended to be protected using TLS 1.2 or higher.
Data at rest is intended to be protected using strong encryption controls appropriate to the hosting and storage environment.
Uploaded files, backups and stored platform records are intended to be protected using encrypted storage or equivalent safeguards where supported.
Role-based access controls, school-level data separation and least-privilege principles are intended to limit unnecessary access.
Administrative accounts are intended to require stronger access protections, including multi-factor authentication where applicable.
5. Authentication and access management
EduSwap uses account authentication controls intended to support secure access by authorised users.
These controls may include secure password hashing, optional single sign-on support, session expiry, session rotation and failed-login monitoring.
Access rights are intended to be limited according to user role, school membership and operational need.
Privileged or sensitive actions may be logged to support auditability and review.
6. Network and infrastructure security
EduSwap’s security posture is intended to include protective controls such as web application firewall coverage, rate limiting, DDoS mitigation and IP-based protections where supported by the hosting environment.
Infrastructure and dependencies are intended to be maintained through secure deployment practices, controlled change processes and vulnerability management.
Source control, code review, CI/CD and dependency scanning are used to support secure software delivery practices.
7. Testing and assurance
EduSwap may use automated vulnerability scanning and other security review processes as part of ongoing development and maintenance.
Independent penetration testing may be undertaken periodically, particularly before major releases or for vendor assessment purposes.
Security findings are intended to be reviewed, prioritised and remediated according to risk and operational impact.
8. Data backup and disaster recovery
Encrypted backups are intended to be taken regularly and retained in Australian data centres.
Backup retention is generally intended to follow a 90-day lifecycle unless a shorter or longer period is required for operational reasons.
EduSwap’s recovery objectives are intended to support timely restoration in the event of service disruption, with indicative targets such as recovery time under 2 hours and recovery point under 1 hour where reasonably achievable.
Incident response and restoration processes are supported by documented operational procedures.
9. Data isolation and school segmentation
EduSwap is designed to enforce strong separation between school accounts and tenant data.
Controls may include tenant-aware application logic, scoped access tokens, school-linked authorisation checks and controlled communication pathways.
These measures are intended to reduce the risk of one school accessing another school’s private data.
10. Privacy-by-design practices
Privacy considerations are intended to be incorporated into platform design, development and operational processes.
This includes minimising unnecessary data collection, restricting internal access, supporting deletion and correction workflows, and considering privacy impacts when introducing new features.
EduSwap is intended to support compliance with applicable Australian privacy requirements and school-sector expectations.
11. Third-party services
EduSwap uses a limited number of service providers for functions such as hosting, email delivery, authentication support and payments.
Third-party services are assessed for suitability, with a preference for providers that support strong security and privacy controls.
EduSwap is not intended to store payment card details directly where card processing is handled by payment processors.
12. Operational security
Operational security practices may include confidentiality requirements, restricted privileged access, change management, staff security awareness and access logging.
Where elevated access is required, it is intended to be granted only to authorised personnel with an operational need.
Security-related events and administrative actions may be logged and reviewed where appropriate.
13. Data breach management
EduSwap’s incident response approach is intended to support rapid containment, assessment, remediation and communication in the event of a security incident.
Where a breach is likely to result in serious harm, EduSwap intends to follow applicable Notifiable Data Breaches obligations, including notification to affected parties and regulators where required.
Post-incident review and remediation actions may be undertaken to reduce the risk of recurrence.
14. Compliance summary
EduSwap’s security approach is intended to align with relevant Australian privacy and cyber security expectations, including APP principles, NDB obligations and school-sector ICT security expectations.
Security practices may also draw on recognised control frameworks such as ISO 27001, NIST Cybersecurity Framework and OWASP guidance where appropriate.
Alignment with these frameworks does not imply certification unless expressly stated.
15. Commitment to continual improvement
EduSwap intends to continue improving its security posture over time through operational review, technical hardening, vendor assessment preparation and ongoing control refinement.
Security controls, processes and documentation may be updated as the platform evolves and as school-sector expectations develop.
16. Contact information
For security assessments, audit enquiries or security-related questions, contact EduSwap Pty Ltd — Security Team.
Email: support@eduswap.com.au