Security & Privacy

Student Data is Sacred.We Protect It Like It Is.

GoHiMark is built for privacy-first procurement: clear data-flow evidence, documented controls, teacher-reviewed AI use, and security milestones schools can inspect.

Privacy reviewAU hosting postureEncryption designACSC mappingIncident workflow

Six Pillars of Security

Security isn't a feature we added — it's embedded in every layer of how GoHiMark works.

Australian Hosting Posture

Australian hosting, sub-processor routing, backups, logs, and AI provider data flows are documented for procurement review.

AU hosting targetData-flow reviewSub-processor register

Encryption at Rest & In Transit

Encryption and key-management controls are captured as reviewable design evidence before stronger certification claims are made.

Encryption designKey-management reviewTransport security

Access Controls & Authentication

Role-based access control ensures teachers only see their own classes, students see only their own data, and administrators have audited elevated access.

RBACMFA enforcedSession managementAudit logging

Procurement Evidence

Privacy, security, and curriculum governance claims are tracked as evidence packs instead of presented as unsupported badges.

Privacy reviewACSC mappingCurriculum governance

Incident Response

Incident response roles, escalation paths, school communications, and NDB assessment steps are maintained as due-diligence documentation.

IR workflowSchool notification pathNDB assessment

Security Validation Roadmap

Internal reviews, third-party testing, and certification work are tracked as validation milestones until formal evidence is attached.

Internal reviewThird-party testing targetEvidence pending

Our Privacy Commitments

We believe student data belongs to students and schools — not to technology companies. These commitments are written into our contracts, not just our marketing.

Australian hosting and offshore-transfer boundaries documented for procurement review

Student data advertising and commercial-use restrictions tracked in the DPA evidence pack

AI training-use restrictions documented for model and vendor review

Data export and deletion workflows documented for contract review

Transparent Data Processing Agreement (DPA) available on request

Privacy Impact Assessment (PIA) documentation available for procurement teams

Compliance Framework Coverage

GoHiMark is designed to satisfy the regulatory and contractual requirements of Australian schools.

FrameworkStatus
Privacy Act 1988 (Cth)Evidence in progress
ACSC Information Security ManualMapped for review
NSW NESA Data GovernanceUnder review
Victorian Education DepartmentMapped for review
Notifiable Data Breaches (NDB)Workflow documented
General Data Protection Regulation (GDPR)Requirements tracked

Security Questions, Answered

Common questions from IT teams and procurement officers.

Have More Security Questions?

Our team is happy to provide documentation for your IT review, complete your security questionnaire, or join a call with your IT director.