AWS, in your region. Australian schools' data stays in Australia.
Your school owns its data. We only process it to run the service.
Handled by Stripe. We never store card details or take a commission.
ST4S assessed; AWS-certified infrastructure; Penetration-tested.
Alumnly is built for schools and institutions, and they are careful about the data. We think that scrutiny is a good thing. The answers below are the ones we give when a school's IT or business team runs their due diligence, written in simple and plain language. If your team needs more detail than this page offers, we're happy to answer or talk it through directly.
This is the question schools ask first, and the answer is simple: the data belongs to you, not to us.
Your school is the data controller. Alumnly is the processor - which means we handle your alumni's personal information only to provide, operate, secure, support and maintain the service you're paying for. That's the whole of it.
Our Terms grant Alumnly a licence to host, store, display and transmit your content. That licence exists for one reason only: so the platform can technically function - show a profile, send an event invitation, back up a photo, and such. It does not transfer ownership, and it does not give us any right to exploit your data commercially. Ownership stays with your school.
Alumnly runs entirely on Amazon Web Services (AWS), one of the most secure and widely
trusted cloud platforms in the world.
Your data is hosted in the AWS Sydney region. Your production data, backups, and processing all remain in Australia.
We support deployment in the AWS London region for institutions with UK or EU data - residency requirements.
Where an institution needs its data in a specific jurisdiction, we can support custom-hosted arrangements.
Whichever region applies to you, your data, backups and processing remain within it. Data doesn't quietly move regions.
Alumnly serves hundreds of institutions on shared infrastructure — but no school can ever see another school's data. That separation is enforced at every layer, not left to chance.
Security isn't one feature — it's layers. Here's what protects your data day to day.
Data is encrypted in transit and at rest, so it's protected both as it travels and where it's stored.
Role-based access means people only see what their role allows.
Multi-factor authentication is enforced for administrator level accounts.
Infrastructure and application activity are continuously monitored, with audit logging and threat detection across the environment.
Data is backed up within your hosting region, with recovery arrangements to restore service if something goes wrong.
All payments run directly through Stripe, a PCI DSS Level 1 provider. Alumnly never stores card details and takes no commission.
Where a school connects a SIS, staff and admin access can be managed and revoked automatically as people join or leave.
We're honest about what sits where:
Alumnly is built on AWS infrastructure backed by globally recognised security certifications. At the application and organisational level, our security practices are independently validated through ST4S assessment and regular penetration testing. We believe in being clear about our security credentials, so schools know exactly what has been independently assessed and where each assurance applies.
Our Terms and Privacy Policy are professionally drafted and written to protect the schools we serve.
Alumni agree to the Terms and Privacy Policy when they join, and a consent reminder appears on every login. We review and update these policies whenever we release new features or major enhancements, and we notify schools by email when we do. We're glad to fit in with your own supplier-review cycle.
Read the full Privacy Policy and Terms & Conditions at alumnly.com/privacy, and alumnly.com/terms- conditions. Further detail on our security practices is at alumnly.com/cybersecurity, and our data breach policy and process at alumnly.com/data-breach-policy-and-process.
No platform can promise nothing will ever happen. What matters is what a supplier does when it does.
Alumnly maintains internal information security, security incident management, and data breach policies, and a published data breach process. In the event of an incident affecting a school's data, our process covers containment, assessment, and notification to the affected institution, so your school is informed and supported rather than left in the dark.
This page describes Alumnly's general approach and is provided for information. Specific arrangements for your institution are governed by your agreement with Alumnly.
Send us your security questionnaire or book a call with our team. We're glad to help your assessment along.