1. Scope and Governance
This Security Policy describes the technical and operational controls used by TeacherAI to protect school, teacher, and student information.
TeacherAI is operated by Sky Network Pty Ltd. This policy applies to production services, including web application access, account management, learning data, and related support processes.
2. Data Residency and Service Providers
- Primary production database is hosted in Sydney, Australia (DigitalOcean).
- Payment processing for teacher subscriptions is handled by Stripe.
- Student learning data is stored in TeacherAI systems and is not used by TeacherAI to train AI models.
- Current subprocessors and service providers are published at /subprocessors.
- AI inference requests are processed by providers whose servers are located outside Australia (primarily United States). These requests use zero data retention configurations where available and supported by provider/account settings, and do not intentionally include student personally identifiable information. See the Privacy Policy Section 4.6 for full cross-border disclosure under APP 8.
3. Data Protection Controls
- Encryption in transit using HTTPS/TLS.
- Encrypted storage for production data at rest.
- Passwords are stored as salted cryptographic hashes.
- Input validation and server-side authorization checks are applied on protected actions.
4. Identity and Access Management
- Role-based access controls separate admin, teacher, and student permissions.
- Authenticated sessions are required for protected features and APIs.
- Administrative actions are restricted to authorized staff with least-privilege principles.
- Privileged activity is logged and reviewable in administrative security views.
- Student-facing AI chat access can be controlled at class level and overridden at organization-wide level.
5. Platform Security Operations
- Security-relevant logs and suspicious activity patterns are monitored.
- Identified vulnerabilities are triaged and remediated according to risk.
- Backups and recovery processes are maintained for service continuity.
- Security updates and dependency updates are applied as part of ongoing maintenance.
- Security logs are retained for operational investigation and compliance support.
6. Incident Response and Notification
Security incidents are managed through internal response procedures covering identification, containment, remediation, and post-incident review. Our notification obligations are aligned with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988.
- Incidents affecting confidentiality, integrity, or availability are escalated for investigation.
- Where school data is materially impacted, TeacherAI targets initial notice to the affected school contact within 72 hours of confirming the incident.
- Where an eligible data breach is identified, we notify the Office of the Australian Information Commissioner (OAIC) as required under the NDB scheme.
- Notifications include known impact, affected data categories, containment actions, and next steps.
- We cooperate with affected schools so they can meet their own breach notification obligations to students, parents, and staff.
- Status updates are provided as material information becomes available until containment is complete.
7. Retention, Deletion, and Review
- Data retention and deletion settings are governed by the Privacy Policy and school requirements.
- Access permissions are reviewed and updated as roles or class assignments change.
- Administrative access is reviewed at least annually and when staffing changes occur.
- This Security Policy is reviewed at least annually and updated as controls evolve.
8. School Compliance Support
- Schools may request a Data Processing Addendum (DPA) for local risk and procurement requirements.
- On request, TeacherAI can provide policy links, data handling summaries, and provider transparency details for school assessments.
- Compliance resources are available at /compliance.
- ST4S outcomes are advisory and commonly medium-risk; schools remain responsible for local consent and approval workflows.
- When student-facing AI is disabled by school settings, student AI prompts are not sent to AI providers via those disabled features.
- Where AI-enabled checks are used, processing is limited to lesson/assessment content and excludes student personal information.
- When enabled, student AI chat is available only within active lessons and is constrained to current lesson topic, lesson content, and activity context.
- Student AI chat is designed to guide understanding rather than provide direct answer-only responses.
- Chat UI history is persisted locally in the browser for user experience.
- TeacherAI stores full server-side AI chat transcripts (student messages and AI responses) for child safety, school audit, and regulatory compliance, with a minimum 12-month retention period. A separate minimal topic summary is stored for rate limiting with 90-day automated cleanup. See the Privacy Policy Sections 2.6 and 9 for details.
- TeacherAI supports organization-level and class-level AI controls, including broader AI feature disablement where required by school policy.
- TeacherAI is an AI-capable platform; however, DOE implementations can be configured to operate in LMS-only mode.
- For DOE-domain organizations, student AI chat is configured as disabled by default at organization and class level controls.
- Teacher AI-assisted marking and assessment tools remain available unless the school elects to disable those features in line with local policy.
- AI-assisted marking is optional and assistive only. TeacherAI does not warrant that AI-assisted outputs are accurate, complete, or error-free.
- Schools and teachers must not rely on AI-assisted outputs as the sole basis for grading or reporting decisions.
- Teachers and schools are responsible for final grading decisions and professional judgement, and should export/download and retain assessment records and submitted work (where available in the Service) in their own reporting systems for safekeeping and audit.
- Practice Sets: auto-grading of structured questions (multiple-choice, matching, ordering, etc.) is performed within TeacherAI systems. AI feedback on open-ended questions is processed via approved AI providers using zero data retention where available and supported by provider/account settings. Adaptive difficulty and mastery scoring are calculated internally.
- Whiteboard and Annotation: teacher drawings and annotations are broadcast to students in real time and may be saved as snapshots with optional audio/video. Whiteboard data is stored on Australian servers and is not processed by external AI providers. Ephemeral data expires after the lesson session; saved snapshots are cleaned up after 6 months (active classes) or 3 months (archived classes).
9. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities from researchers, school IT staff, and the public. If you discover a potential vulnerability:
- Email: [email protected] with details of the issue
- We will acknowledge receipt within 48 hours
- We will work to confirm and remediate confirmed vulnerabilities promptly
- We will not take legal action against good-faith security researchers who follow responsible disclosure practices
For general security questions or to report a suspected data breach, contact us at the same address or via /contact.
This page is a summary of current security controls and may be updated over time. Contractual and regulatory obligations are defined by applicable agreements and law.