Legal
Trust & security
Last updated 4 July 2026
PupilRoute handles sensitive information about children with special educational needs and disabilities. This page is the summary a buyer's information governance team reads first: what we hold, where it lives, how it is protected, and who else touches it.
Astragrid Technologies Ltd (which operates PupilRoute) holds a current Cyber Essentials certificate, assessed by IASME. Certificate 18afe630-9161-49f6-999e-e0f287b70f27, whole-organisation scope, valid to 3 December 2026. The certificate can be verified through IASME.
At a glance
| Data residency | United Kingdom (London). Database and application both hosted in-region. |
|---|---|
| Our role | Data processor. The local authority is the controller for its pupil data. |
| Tenant isolation | Each authority sees only its own data; enforced in the application and at the database. |
| Access | Invite-only, least-privilege by role, with an immutable audit trail. |
| Encryption | TLS in transit; encryption at rest by the managed platform. |
| Certification | Cyber Essentials (IASME), whole organisation. |
| Special category data | Yes, children's SEND information. A DPIA has been completed. |
| Sub-processors | Four, all UK/EU region (listed below). |
Where your data lives
PupilRoute runs on managed cloud infrastructure in the United Kingdom. The database is hosted in the London (eu-west-2) region and the application functions are pinned to London, so pupil data does not leave the UK in normal operation. We do not sell data or use it to train models.
Keeping authorities separate
PupilRoute is multi-tenant. Every record belongs to one authority, and access is scoped to the signed-in user's authority in two independent layers: the application filters every read and write by the user's authority, and the operational database tables are closed to the public data API so they can only be reached through the application. One council can never see another council's pupils, routes or spend.
Who can get in
- Invite-only. No sign-in of any kind grants access unless an administrator has provisioned an account for that person. This applies to Google, Microsoft and email logins alike.
- Least privilege. Roles (Admin, Planner, Caseworker, Viewer) grant only the access each job needs; finance users are read-only.
- Credential hygiene. First-login users must set their own password; self-service password reset is available; there are no shared logins.
- Accountability. Every change is stamped with the user's identity and appended to an immutable audit trail.
Encryption and platform security
Traffic to and within the service is encrypted with TLS. Data at rest is encrypted by the managed database and hosting platforms. We hold no card data. Our organisation-wide technical controls (firewalling, patching, malware protection, secure configuration and access control) are assessed annually under Cyber Essentials.
Sub-processors
We use a small number of carefully chosen providers. All operate in the UK/EU region.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Managed Postgres database and authentication | UK (London, eu-west-2) |
| Vercel | Application hosting | UK (London, lhr1) |
| Brevo | Transactional email (invitations, password resets) | EU |
| Web3Forms | Marketing enquiry form delivery | EU / global edge |
Google and Microsoft are used only where an authority chooses single sign-on with its own organisation accounts. We give advance notice of any change to this list under our Data Processing Agreement.
Data protection
As processor we act only on the controlling authority's documented instructions. We support data subject requests, and we operate a breach procedure that meets the 72-hour notification duty. Our privacy notice, terms and accessibility statement are public; the Data Processing Agreement, security overview, Record of Processing, retention schedule, sub-processor register and DPIA are shared with customers on request.
Resilience
The managed database is backed up by the platform with point-in-time recovery. The application is stateless and redeploys from source control, so it can be restored quickly. The public demonstration uses synthetic data only.
Reporting a concern
To report a security issue or ask an assurance question, contact misi@pupilroute.uk. We aim to acknowledge security reports within one working day.