Security & Privacy

Student Data is Sacred.We Protect It Like It Is.

GoHiMark was built privacy-first. Australian data centres, encrypted storage, strict access controls, and a commitment to never selling or misusing student information.

Privacy Act 1988AUS Data CentresAES-256 EncryptionACSC Aligned72hr Breach Notification

Six Pillars of Security

Security isn't a feature we added — it's embedded in every layer of how GoHiMark works.

Australian Data Residency

All student data is stored exclusively in Australian data centres located in Sydney and Melbourne. We never transfer student data offshore.

AWS ap-southeast-2 (Sydney)AWS ap-southeast-4 (Melbourne)No offshore transfers

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed in AWS KMS with automatic rotation.

AES-256 encryptionTLS 1.3AWS KMS key management

Access Controls & Authentication

Role-based access control ensures teachers only see their own classes, students see only their own data, and administrators have audited elevated access.

RBACMFA enforcedSession managementAudit logging

Compliance Frameworks

GoHiMark is designed to meet Australian privacy and security requirements for educational institutions.

Privacy Act 1988ACSC ISM alignedNESA guidelinesVCAA requirements

Incident Response

Dedicated security incident response team with documented procedures. Data breach notification within 72 hours as required under the Notifiable Data Breaches scheme.

72hr breach notificationOAIC compliantDocumented IR plan

Penetration Testing & Audits

Annual third-party penetration testing by CREST-certified security firms. Internal security reviews conducted quarterly.

Annual pen testingCREST-certified firmQuarterly reviews

Our Privacy Commitments

We believe student data belongs to students and schools — not to technology companies. These commitments are written into our contracts, not just our marketing.

All data stored in Australian data centres — no offshore transfers ever

Student data is never sold, shared with advertisers, or used for any commercial purpose outside GoHiMark

Student data is never used to train any external AI model

You own your data — export or delete it at any time, including after contract termination

Transparent Data Processing Agreement (DPA) available on request

Privacy Impact Assessment (PIA) documentation available for procurement teams

Compliance Framework Coverage

GoHiMark is designed to satisfy the regulatory and contractual requirements of Australian schools.

FrameworkStatus
Privacy Act 1988 (Cth)Compliant
ACSC Information Security ManualAligned
NSW NESA Data GovernanceCompliant
Victorian Education DepartmentAligned
Notifiable Data Breaches (NDB)Compliant
General Data Protection Regulation (GDPR)Compliant

Security Questions, Answered

Common questions from IT teams and procurement officers.

Have More Security Questions?

Our team is happy to provide documentation for your IT review, complete your security questionnaire, or join a call with your IT director.