TRUST & SECURITY

Built for school procurement. Designed for parent trust.

PAGS is Cyber Essentials and Cyber Essentials Plus certified. Hosted in the EU, encrypted at every layer, and architected around the data protection requirements that UK and European schools must meet.

Independently verified: click a badge to view live certificate
HostingMicrosoft Azure
Validated byUCL
Assessed byIASME
Aligned withUK ICO Children’s Code
MIS partnersWonde, IRIS

Certified. Audited. Inherited.

Three layers of independent attestation, from the platform we run on, to the company that runs it, to the science behind the assessments.

How we protect your data.

The technical and operational controls that sit between school data and anyone who shouldn’t see it.

Control
What we do
Encryption
Encryption at rest
AES-256 via Azure-managed disk encryption. Applied automatically to all databases, storage, and backups.
Encryption in transit
TLS 1.2+ on every endpoint, secured by valid certificates from a trusted Certificate Authority. No unencrypted traffic.
Access
Multi-factor authentication
Enforced for all administrator access to the Azure environment. Available to schools for end-user accounts using Microsoft or Google Authenticator.
Role-based access control
Every user is scoped to their school or trust. No cross-tenant access. Trust-level users can access multiple schools only when explicitly granted by an organisation admin.
Secret management
All credentials, API keys, and connection strings live in Azure Key Vault. None are stored in code or configuration files.
Network & operations
Network protection
Azure firewall rules, private endpoints, and DDoS protection. No RDP, SSH, or other administrative ports exposed to the public internet.
Audit logging
All administrative actions, user logins, permission changes, and data interactions are logged in Azure and within the platform itself.
Secure development
Peer-reviewed pull requests, separated dev, staging, and production environments. Least-privilege access for engineers. Static analysis and vulnerability scanning via Azure-native tooling.

Hosting and infrastructure.

The PAGS platform runs entirely on Microsoft Azure. There is no on-premise infrastructure, no shared hosting, and no third-party server estate. All services, databases, and storage are provisioned, monitored, and access-controlled within Azure.

School data is stored in the West Europe Azure region (Amsterdam, Netherlands) and is not transferred outside the EU unless explicitly authorised by the customer. Azure is certified to ISO 27001, ISO 27018, and SOC 1, SOC 2, and SOC 3, with physical security, infrastructure patching, and resilience managed by Microsoft.

Network protection is enforced through Azure firewall rules, private endpoints, and DDoS mitigation. No administrative ports, including RDP and SSH, are exposed to the public internet. Internal service-to-service traffic uses encrypted channels managed by Azure. End users access the platform through a secure, browser-based portal at https://www.pagsprofile.com, with no local plugins or installations required.

Operating-system-level and infrastructure updates are applied continuously by Microsoft. Application-layer patches are released by PAGS through a peer-reviewed pull request process and deployed through separated staging and production environments.

Backup, continuity, and recovery.

Every critical PAGS dataset is backed up on an hourly schedule using Azure geo-redundant storage, with a 31-day retention window. Backups are encrypted at rest, separated from production systems, and accessible only to authorised administrators through role-based controls.

If a restoration is required, point-in-time recovery is available across the full 31-day window. Recovery time objective for core platform services is two to four hours during business hours, assuming the Azure environment remains accessible.

Against ransomware specifically, the platform inherits Azure-native protections including immutable blob storage, soft-delete for accidental or malicious deletions, and built-in threat detection. Backup configuration is access-controlled and isolated from the production application surface, preventing an attacker who compromises the application from also compromising the backups.

A formal disaster recovery plan documents the procedures, roles, recovery time objectives, and customer communication protocols. The plan is reviewed and refined as the platform scales.

GDPR and data protection.

PAGS is a UK and EU GDPR-compliant processor of personal data. Schools and trusts are the data controller for learner and staff records; PAGS BV is the data processor, operating under a Data Processing Agreement with every customer.

Personal data is processed under the lawful basis the customer specifies, typically Article 6(1)(e) public task for state-funded schools, or Article 6(1)(b) contract for independent schools. The platform applies data minimisation by design, holds learner records only for purposes the school has authorised, and retains data for the duration of the customer relationship plus any agreed exit window.

Data subject access requests, including parental and learner rights to access, rectify, or erase personal data, are handled in coordination with the customer. PAGS provides the technical means within the platform; the school as controller makes the disclosure decisions.

International transfers are avoided by default. School data is stored in the West Europe Azure region and not transferred outside the EU unless explicitly authorised by the customer. Where any sub-processor operates outside the EU, transfers are governed by Standard Contractual Clauses or equivalent safeguards.

Sub-processors

PAGS keeps the sub-processor list deliberately short. Each processor is vetted for legal safeguards and contractually required to meet equivalent data protection obligations.

A complete and current sub-processor list is available to procurement teams on request.

Sub-processor
Purpose & data shared
Microsoft AzureWest Europe, Amsterdam
Cloud hosting, storage, backup, identity, and infrastructure security. Encrypted data at rest and in transit. Governed by Microsoft enterprise DPA. ISO 27001 certified processing.
Microsoft Azure OpenAI ServiceWest Europe
AI-assisted target, strategy, and EHCP scan features. Receives only anonymised, instructional descriptors via the Microsoft Presidio anonymisation layer. No personal data is sent. Data does not leave Azure and is not used to train Microsoft or OpenAI models.
Wonde
Optional, customer-opt-in MIS integration for syncing learner identity data from school information systems. Read-only, encrypted API access; no data transmitted without explicit school authorisation.
IRIS EducationiSAMS, IRIS Ed:gen
Optional, customer-opt-in integration partner. Read-only API sync of learner identity data where the school is an IRIS customer. Credentials secured in Azure Key Vault; activity logged.

AI processing.

PAGS uses AI to assist with target generation, intervention strategies, curriculum overlays, and EHCP document scanning. The pipeline has been designed so that learner identity is protected before any AI model ever sees the data.

1
Teacher input
SENCO writes targets or uploads an EHCP document inside PAGS.
2
Presidio anonymises
Microsoft Presidio strips all PII, names, dates of birth, and other identifiers before transmission.
3
Azure OpenAI
Anonymised descriptors only. Processed in the EU region. Not used to train Microsoft or OpenAI models.
4
SENCO reviews
Every AI suggestion is reviewed by a human before it can be applied.
5
Applied to record
Only validated outputs are written back to the learner record.

AI features run on the Microsoft Azure OpenAI Service in the West Europe region. Before any learner data is sent to the model, it passes through an anonymisation layer powered by Microsoft Presidio, which automatically detects and removes personally identifiable information including learner names, dates of birth, and other identifiers. The model receives only generalised, instructional, or target-related descriptors. No PII is included in prompts.

Data sent to Azure OpenAI does not leave the Azure infrastructure, is not stored beyond the request, and is not used to train Microsoft or OpenAI models. The Microsoft enterprise Data Processing Agreement governs this processing.

Every AI-generated suggestion is reviewed by a human, a SENCO or teacher, before it is applied to a learner record. The platform requires this human-in-the-loop step. No AI output is automatically written into learner records without that validation. PAGS’ internal AI policy includes ethical review and explicitly prohibits using AI to make decisions on a child’s behalf.

This approach is documented and risk-assessed in the PAGS Data Protection Impact Assessment, which is available to procurement teams on request.

Children’s data.

The PAGS platform processes data about children. We take that responsibility seriously and design the platform around the principle that children’s information is for safeguarding and educational purposes only.

School and trust customers determine the purposes and means of processing, with PAGS as the processor. We do not advertise to children. We do not profile children for marketing purposes. We do not sell, share, or resell learner data to any third party. Personal data is used only for the platform purposes the customer has agreed to.

The Parent Portal is invitation-only. A parent or carer can only access a child’s record once the school has explicitly invited them. Access is scoped to that specific child, with no visibility of other learners or staff.

Our practices are designed in line with the UK ICO’s Age Appropriate Design Code, including privacy by default, no nudge techniques, no use of personal data beyond the educational purpose, and clear, accessible information for parents and carers.

Vulnerability management.

Vulnerability management combines continuous platform-level scanning with annual external verification.

The Cyber Essentials Plus certification requires an independent assessor to verify, hands-on, that multi-factor authentication is enforced, that operating systems and applications are patched within agreed windows, that secure configuration is applied, that malware protection is active, and that access controls are correctly scoped. PAGS passes this verification annually.

Day-to-day, Microsoft Azure continuously scans the underlying infrastructure for known misconfigurations, exposed services, and emerging vulnerabilities. Azure-native tooling, including Activity Logs and Diagnostics, surfaces unusual events to the technical team for review.

To report a potential security issue, contact support@pagsprofile.com. We welcome responsible disclosure and will acknowledge reports within two working days.

For procurement teams.

Everything a school IT lead, DPO, or trust procurement team typically asks for, available from one contact.

Document or evidence
How to get it
Cyber Essentials certificate
Verifiable on the official Blockmark registry (see badge above) or by request as a PDF.
Cyber Essentials Plus certificate
Verifiable on the official Blockmark registry (see badge above) or by request as a PDF.
Data Processing Agreement (DPA)
Standard PAGS DPA template provided to every customer. Available on request before contract.
Full security questionnaire (SAQ) responses
Comprehensive cloud security and infrastructure questionnaire available on request.
Sub-processor list
Current, version-dated list available on request.
Customer reference call
Available with existing schools and trusts. Arranged through your account contact.
Data Protection Impact Assessment (DPIA)
Current DPIA (May 2026, v1.2) covering the platform and AI features available to procurement teams on request.

Procurement contact: info@pagsprofile.com

Security is layered. No single control carries the risk alone.

Five layers work together, from governance policy to real-time monitoring.

Five layers of security: governance and assurance, identity and access, encryption and data protection, secure hosting and recovery, and monitoring, testing and response.

Talk to our procurement team.

Whether you are vetting PAGS for the first time, refreshing a DPA, or running a trust-wide security review, our team will give you the documents, the answers, and the verification links your DPO and IT lead need.

PAGS is operated by PAGS BV, a company registered in Belgium (registered office: Allee de la Recherche, Anderlecht, Brussels 1070; company number 0761801376). This page describes the operational, technical, and contractual practices in place at the time of writing. Last reviewed: June 2026.