Every decision we've made about how Orca is built and hosted has been made with school data security in mind. From the technologies we've chosen to the infrastructure we run on, your school's data is protected by enterprise-grade, independently certified security at every level.
Orca is built on a layered security model. Rather than building security from scratch, we've chosen best-in-class providers at every level (each holding internationally recognised, independently audited security certifications) and added our own application-level controls on top.
Our server infrastructure is provided by a cloud hosting provider that holds SOC 2 Type II certification, independently audited against internationally recognised security standards for data security, availability and confidentiality. The underlying data centre facilities are certified to ISO 27001, the international standard for information security management.
Orca runs on Amazon Web Services, which provides the network firewalling, the physical and hypervisor layers, and fully managed patching of the database. Above that, Orca operates the application and operating system: servers install security updates automatically every night, run a host firewall that denies all unsolicited inbound traffic, accept administrative access only by cryptographic key, and automatically block repeated failed login attempts.
Orca is built using proven, industry-standard technologies with strong security track records. Security is treated as a first-class concern throughout development, not an afterthought. Our application enforces strict access controls, encrypted communications and privacy-by-design principles at every layer.
All Orca data is stored and processed in Australia. Student, staff and parent records, activity records, risk assessments, alerts, forms and uploaded files stay onshore. So does AI processing: where a school has enabled Orca's optional AI features, requests are handled by Microsoft Azure OpenAI in the Australia East region. AI features are off by default. Our AI Data Processing Fact Sheet sets out how AI requests are handled in full.
Beyond the infrastructure, Orca itself is built with security and privacy at its core.
We strongly recommend (and fully support) Single Sign-On for all school users. SSO means your staff and students authenticate through your school's existing identity provider, removing the need to manage separate Orca passwords and reducing the risk of credential-based breaches.
Orca enforces role-based access within the application. Users only see the data and features relevant to their role. Administrators, coordinators, teachers and students each have clearly defined and limited access, following the principle of least privilege.
All data transmitted between your browser and Orca is encrypted using TLS (Transport Layer Security). Data at rest is encrypted with AES-256 at the infrastructure level by Amazon Web Services.
Regular automated backups are taken using Amazon Web Services’ native snapshot facilities, supporting recovery in the event of data loss or a system incident.
Privacy is built into Orca from the ground up, not bolted on. The system is designed to collect only the data needed to run the service, enforce access boundaries at the application level, and support schools in meeting their obligations under the Australian Privacy Act 1988, including the ability to action data access, correction and deletion requests.
User and activity data is stored in a robust, enterprise-grade relational database, patched by Amazon Web Services as a managed service, on a hardened server environment that installs security updates automatically every night.
Orca's AI features are switched off by default and can be disabled for your school at any time on request. Where they are enabled, requests are processed by Microsoft Azure OpenAI in Australia, and Orca sends only the specific fields each feature needs. Student alert content, incident narratives and uploaded files are never sent. Your data is never used to train AI models, and every AI suggestion is reviewed by a staff member before it takes effect. Our AI Data Processing Fact Sheet, setting out exactly what an AI request may and may not contain, is available to schools on request.
When your school uses Orca, you are the data controller. Orca acts as a data processor: we handle your data only to deliver the service, and only in accordance with the terms you've agreed to.
We will never sell or monetise your school's data or your students' data, and we never disclose it to third parties for advertising or profiling. We collect only what is needed to run the service, and we use a small number of named sub-processors to deliver it. These are listed in our Privacy Policy.
You have the right to request a copy of your data, ask us to correct or delete data, and receive a plain-language answer to any question about how your information is used.
We're happy to answer any questions about how Orca handles your school's data. If you're a school IT manager or privacy officer conducting due diligence, we can provide further documentation on request, including details of our cloud infrastructure provider and its certifications, and our AI Data Processing Fact Sheet.
Orca is operated in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Certification references on this page relate to Orca's cloud infrastructure provider. Full sub-processor details are available to schools on request.
See how Orca transforms activity management at your school. Book a personalised demo and we'll walk you through exactly how Orca fits your workflows.