The problem

School data is a target, and a trust.

Alumni records aren’t a marketing list. They hold names, contact details, family connections and giving histories — often for people who were children when the school first met them. That makes the data both valuable to an attacker and precious to the community it belongs to. So the questions an IT director should ask are fair and simple: where does the data live, who can reach it, what happens if something goes wrong, and can we take it back. The rest of this page answers each one.

 

100%
Of your records are exportable to Excel on request. No part of your data is held hostage.
How it is protected

The controls, plainly stated.

Encryption everywhere

Encrypted at rest and in transit. Connections secured with SHA-256 TLS, so traffic can’t be read in flight.

WAF & intrusion detection

A web application firewall in front of the platform, paired with intrusion detection to filter hostile traffic and surface suspicious activity early.

CSP & HSTS

A Content Security Policy and HTTP Strict Transport Security enforced at the browser, reducing the surface for injection and downgrade attacks.

Patching & backups

Systems patched on a regular cadence and backed up routinely, so the platform stays current and recoverable.

Scanning & pen testing

Vulnerability scanning runs against the platform, and penetration testing probes for weaknesses before an attacker can.

Security education

User security education is documented and part of how the team works — because the strongest controls still depend on the people operating them.

it-img-box
Data residency

Hosted in Australia. Stays in Australia.

Alumnly runs on AWS in the Sydney region. Your records are stored and processed within Australian and New Zealand jurisdiction, which keeps you aligned with local privacy expectations and removes the offshore-transfer question from your review entirely. It’s the same answer for every plan, from the smallest school to the largest.

Compliance & assessment

Independently assessed, not self-declared.

Safer Technologies 4 Schools

Alumnly carries the ST4S 2026 badge — the national framework that assesses school technology against a shared privacy and security standard.

Notifiable Data Breach scheme

Alumnly operates in line with the Australian NDB scheme, with a documented breach response that meets its notification obligations.

Encryption & transport security

Encryption at rest and in transit, SHA-256 TLS, WAF, intrusion detection, CSP and HSTS — all enforced in production today.

Payments via Stripe direct

Card payments handled directly by Stripe, a PCI-certified processor. Alumnly doesn’t store raw card data or skim transactions.

Ownership & portability

Your records, on your terms.

Full excel export

Your complete records export to CSV on request — data you put in is data you can take out, in a format any system can read.

Stripe direct, no skim

Payments run through Stripe directly to your account. Alumnly takes no cut of donations or transactions.

No lock-in

No setup fees, no transaction skim, no lock-in contracts. The relationship is held by the value of the platform, not the cost of leaving.

If the worst happens

A documented, five-step response.

1

Identify

Detect and confirm the incident, and establish what data may be involved.

2

Contain

Limit the exposure and stop the incident spreading further.

3

Assess

Evaluate the scope and the risk of serious harm to those affected.

4

Notify

Inform affected parties and the regulator in line with the NDB scheme.

5

Review

Learn from the event and strengthen controls to prevent a repeat.

Bring us your security questionnaire.

If your review needs documentation, a dated status on anything still in progress, or a conversation with the people who run the platform, we’re glad to provide it. Honest answers, in writing, on your timeline.