PAGS is Cyber Essentials and Cyber Essentials Plus certified. Hosted in the EU, encrypted at every layer, and architected around the data protection requirements that UK and European schools must meet.
Three layers of independent attestation, from the platform we run on, to the company that runs it, to the science behind the assessments.
PAGS BV is certified under the UK government Cyber Essentials scheme, run by the NCSC and assessed via IASME, and holds Cyber Essentials Plus — the hands-on, technically verified version. An external assessor reviews live evidence of MFA enforcement, patch management, secure configuration, malware protection, and access control across the whole organisation. Renewed annually.
The assessment science underpinning PAGS has been independently validated by researchers at University College London. The platform combines that research base with operational tooling for SENCOs and inclusion teams.
The PAGS platform runs entirely on Microsoft Azure, which is certified to ISO 27001, ISO 27018 (cloud privacy), and SOC 1, SOC 2, and SOC 3. Azure manages physical security, infrastructure patching, and resilience across geo-redundant data centres.
The technical and operational controls that sit between school data and anyone who shouldn’t see it.
The PAGS platform runs entirely on Microsoft Azure. There is no on-premise infrastructure, no shared hosting, and no third-party server estate. All services, databases, and storage are provisioned, monitored, and access-controlled within Azure.
School data is stored in the West Europe Azure region (Amsterdam, Netherlands) and is not transferred outside the EU unless explicitly authorised by the customer. Azure is certified to ISO 27001, ISO 27018, and SOC 1, SOC 2, and SOC 3, with physical security, infrastructure patching, and resilience managed by Microsoft.
Network protection is enforced through Azure firewall rules, private endpoints, and DDoS mitigation. No administrative ports, including RDP and SSH, are exposed to the public internet. Internal service-to-service traffic uses encrypted channels managed by Azure. End users access the platform through a secure, browser-based portal at https://www.pagsprofile.com, with no local plugins or installations required.
Operating-system-level and infrastructure updates are applied continuously by Microsoft. Application-layer patches are released by PAGS through a peer-reviewed pull request process and deployed through separated staging and production environments.
Every critical PAGS dataset is backed up on an hourly schedule using Azure geo-redundant storage, with a 31-day retention window. Backups are encrypted at rest, separated from production systems, and accessible only to authorised administrators through role-based controls.
If a restoration is required, point-in-time recovery is available across the full 31-day window. Recovery time objective for core platform services is two to four hours during business hours, assuming the Azure environment remains accessible.
Against ransomware specifically, the platform inherits Azure-native protections including immutable blob storage, soft-delete for accidental or malicious deletions, and built-in threat detection. Backup configuration is access-controlled and isolated from the production application surface, preventing an attacker who compromises the application from also compromising the backups.
A formal disaster recovery plan documents the procedures, roles, recovery time objectives, and customer communication protocols. The plan is reviewed and refined as the platform scales.
PAGS is a UK and EU GDPR-compliant processor of personal data. Schools and trusts are the data controller for learner and staff records; PAGS BV is the data processor, operating under a Data Processing Agreement with every customer.
Personal data is processed under the lawful basis the customer specifies, typically Article 6(1)(e) public task for state-funded schools, or Article 6(1)(b) contract for independent schools. The platform applies data minimisation by design, holds learner records only for purposes the school has authorised, and retains data for the duration of the customer relationship plus any agreed exit window.
Data subject access requests, including parental and learner rights to access, rectify, or erase personal data, are handled in coordination with the customer. PAGS provides the technical means within the platform; the school as controller makes the disclosure decisions.
International transfers are avoided by default. School data is stored in the West Europe Azure region and not transferred outside the EU unless explicitly authorised by the customer. Where any sub-processor operates outside the EU, transfers are governed by Standard Contractual Clauses or equivalent safeguards.
PAGS keeps the sub-processor list deliberately short. Each processor is vetted for legal safeguards and contractually required to meet equivalent data protection obligations.
A complete and current sub-processor list is available to procurement teams on request.
PAGS uses AI to assist with target generation, intervention strategies, curriculum overlays, and EHCP document scanning. The pipeline has been designed so that learner identity is protected before any AI model ever sees the data.
AI features run on the Microsoft Azure OpenAI Service in the West Europe region. Before any learner data is sent to the model, it passes through an anonymisation layer powered by Microsoft Presidio, which automatically detects and removes personally identifiable information including learner names, dates of birth, and other identifiers. The model receives only generalised, instructional, or target-related descriptors. No PII is included in prompts.
Data sent to Azure OpenAI does not leave the Azure infrastructure, is not stored beyond the request, and is not used to train Microsoft or OpenAI models. The Microsoft enterprise Data Processing Agreement governs this processing.
Every AI-generated suggestion is reviewed by a human, a SENCO or teacher, before it is applied to a learner record. The platform requires this human-in-the-loop step. No AI output is automatically written into learner records without that validation. PAGS’ internal AI policy includes ethical review and explicitly prohibits using AI to make decisions on a child’s behalf.
This approach is documented and risk-assessed in the PAGS Data Protection Impact Assessment, which is available to procurement teams on request.
The PAGS platform processes data about children. We take that responsibility seriously and design the platform around the principle that children’s information is for safeguarding and educational purposes only.
School and trust customers determine the purposes and means of processing, with PAGS as the processor. We do not advertise to children. We do not profile children for marketing purposes. We do not sell, share, or resell learner data to any third party. Personal data is used only for the platform purposes the customer has agreed to.
The Parent Portal is invitation-only. A parent or carer can only access a child’s record once the school has explicitly invited them. Access is scoped to that specific child, with no visibility of other learners or staff.
Our practices are designed in line with the UK ICO’s Age Appropriate Design Code, including privacy by default, no nudge techniques, no use of personal data beyond the educational purpose, and clear, accessible information for parents and carers.
Vulnerability management combines continuous platform-level scanning with annual external verification.
The Cyber Essentials Plus certification requires an independent assessor to verify, hands-on, that multi-factor authentication is enforced, that operating systems and applications are patched within agreed windows, that secure configuration is applied, that malware protection is active, and that access controls are correctly scoped. PAGS passes this verification annually.
Day-to-day, Microsoft Azure continuously scans the underlying infrastructure for known misconfigurations, exposed services, and emerging vulnerabilities. Azure-native tooling, including Activity Logs and Diagnostics, surfaces unusual events to the technical team for review.
To report a potential security issue, contact support@pagsprofile.com. We welcome responsible disclosure and will acknowledge reports within two working days.
Everything a school IT lead, DPO, or trust procurement team typically asks for, available from one contact.
Procurement contact: info@pagsprofile.com
Five layers work together, from governance policy to real-time monitoring.
Whether you are vetting PAGS for the first time, refreshing a DPA, or running a trust-wide security review, our team will give you the documents, the answers, and the verification links your DPO and IT lead need.
PAGS is operated by PAGS BV, a company registered in Belgium (registered office: Allee de la Recherche, Anderlecht, Brussels 1070; company number 0761801376). This page describes the operational, technical, and contractual practices in place at the time of writing. Last reviewed: June 2026.