Alumni records aren’t a marketing list. They hold names, contact details, family connections and giving histories — often for people who were children when the school first met them. That makes the data both valuable to an attacker and precious to the community it belongs to. So the questions an IT director should ask are fair and simple: where does the data live, who can reach it, what happens if something goes wrong, and can we take it back. The rest of this page answers each one.
Encrypted at rest and in transit. Connections secured with SHA-256 TLS, so traffic can’t be read in flight.
A web application firewall in front of the platform, paired with intrusion detection to filter hostile traffic and surface suspicious activity early.
A Content Security Policy and HTTP Strict Transport Security enforced at the browser, reducing the surface for injection and downgrade attacks.
Systems patched on a regular cadence and backed up routinely, so the platform stays current and recoverable.
Vulnerability scanning runs against the platform, and penetration testing probes for weaknesses before an attacker can.
User security education is documented and part of how the team works — because the strongest controls still depend on the people operating them.
Alumnly runs on AWS in the Sydney region. Your records are stored and processed within Australian and New Zealand jurisdiction, which keeps you aligned with local privacy expectations and removes the offshore-transfer question from your review entirely. It’s the same answer for every plan, from the smallest school to the largest.
Alumnly carries the ST4S 2026 badge — the national framework that assesses school technology against a shared privacy and security standard.
Alumnly operates in line with the Australian NDB scheme, with a documented breach response that meets its notification obligations.
Encryption at rest and in transit, SHA-256 TLS, WAF, intrusion detection, CSP and HSTS — all enforced in production today.
Card payments handled directly by Stripe, a PCI-certified processor. Alumnly doesn’t store raw card data or skim transactions.
Alumnly connects with the school information systems common across Australia and New Zealand, so onboarding data flows in cleanly rather than by hand.
Your complete records export to CSV on request — data you put in is data you can take out, in a format any system can read.
Payments run through Stripe directly to your account. Alumnly takes no cut of donations or transactions.
No setup fees, no transaction skim, no lock-in contracts. The relationship is held by the value of the platform, not the cost of leaving.
Detect and confirm the incident, and establish what data may be involved.
Limit the exposure and stop the incident spreading further.
Evaluate the scope and the risk of serious harm to those affected.
Inform affected parties and the regulator in line with the NDB scheme.
Learn from the event and strengthen controls to prevent a repeat.
If your review needs documentation, a dated status on anything still in progress, or a conversation with the people who run the platform, we’re glad to provide it. Honest answers, in writing, on your timeline.