A deeper look at the technology stack underpinning Orca and the security credentials of each layer. We believe schools deserve to understand what they're relying on, not just a badge and a tagline.
Orca is responsible for the application and operating system layer, and operates it directly. Servers install security updates automatically every night, run a host firewall that denies all unsolicited inbound traffic, accept administrative access only by cryptographic key, and automatically block repeated failed login attempts.
Data is encrypted in transit with TLS and at rest with AES-256. The infrastructure beneath this layer is provided by Amazon Web Services, described below.
Server-level controls are applied consistently rather than ad hoc: patching runs on a nightly schedule instead of waiting on someone to remember, the firewall denies inbound traffic by default rather than permitting it by default, and administrative access requires a cryptographic key that cannot be guessed or phished.
Orca runs on Amazon Web Services, which provides the network firewalling, the physical and hypervisor layers, and fully managed patching of the database. Our environment runs in an Australian data centre, meaning all Orca data is physically stored in Australia.
Hosting, storage and backups run entirely on AWS. Microsoft Azure is used for one thing only: processing the optional AI features, in the Australia East region. No Orca records are hosted or stored on Azure. See Data Residency below.
The cloud infrastructure platform holds the following certifications and attestations:
The physical and network infrastructure hosting Orca data has been assessed against globally recognised cloud security standards. Data centre facilities (including physical security, environmental controls and network infrastructure) are certified to ISO 27001.
Orca is a proprietary SaaS product built using proven, industry-standard technologies. Security is a first-class concern throughout our development process, not an afterthought.
Security and privacy requirements are considered at every stage of development. The application is designed to collect only the data necessary to deliver the service, enforce strict access boundaries, and support schools in meeting their obligations under the Australian Privacy Act 1988.
Orca includes built-in tools to support privacy compliance, including the ability to action data access, correction and deletion requests, manage user consent, and enforce data retention policies. These controls are part of the core product, not optional add-ons.
Orca is hosted entirely in Australia. School profiles, user accounts, activity records and uploaded content are stored in an Australian data centre, and all processing, including the optional AI features, takes place within Australia.
The server environment running Orca is built on proven, industry-standard technology with strong, long-standing security credentials.
We run a current Long-Term Support (LTS) server operating system that receives regular security patches and is the industry standard for production server environments.
We use one of the world's most widely deployed web servers, with decades of active security development and community oversight.
User and activity data is stored in a robust, enterprise-grade relational database with a strong security heritage, supporting encrypted connections and fine-grained access control.
All components are kept up to date with security patches, installed automatically every night.
We strongly recommend schools connect Orca via SSO through their existing identity provider (Microsoft Entra ID / Azure AD, Google Workspace, or similar). SSO means no separate passwords, authentication governed by your school's own security policies and MFA settings, and automatic account management as people join or leave.
Our platform supports MFA natively. When SSO is used, MFA is inherited from the school's identity provider. For installations not using SSO, MFA can be enabled at the platform level.
Orca enforces role-based access within the application. Each user role (Administrator, Coordinator, Teacher, Student) is granted only the permissions necessary for their function. Access to student data is restricted to users with a legitimate need.
Automated Backups: Orca environments are backed up automatically on a regular schedule using Amazon Web Services’ native snapshot facilities. Backups include the database and application files, and are retained to support recovery from data loss, accidental deletion or system incidents.
Recovery: In the event of a data loss incident, backups can be used to restore the Orca environment. Schools can contact us to initiate a restore or to request confirmation of backup status and scheduling.
All Orca data — school profiles, user accounts, activity records and any uploaded content — is stored and processed within Australia.
This includes AI processing. Where a school has enabled Orca's optional AI features, the contents of individual AI requests are processed in Australia. Records, uploaded files, student alert content and form responses are never transmitted at all, and AI features are off by default.
The Orca platform does not use content delivery networks or analytics platforms that route Australian school data through overseas servers.
Full detail on how AI requests are handled is set out in our AI Data Processing Fact Sheet.
Schools conducting security due diligence are welcome to contact us. We can provide:
See how Orca transforms activity management at your school. Book a personalised demo and we'll walk you through exactly how Orca fits your workflows.