Assurance Partner

Trust,
verified externally.

Independent security auditors and academic-integrity specialists give every exam system, research dataset and student record a second set of eyes before it goes live.

Why this partnership exists

We don't grade our own homework on security or integrity. Third-party auditors review the systems our own team already holds to a high bar.

Independent audits | SOC 2 & GDPR aligned | Continuous review

Why the partnership exists.

A security review is only credible when it isn't written by the team being reviewed.

Internal review catches a lot, but it has a blind spot: it's shaped by the same assumptions that built the system in the first place.

So every system handling student records, exams or research data goes through partners whose only job is to confirm it holds up, independently and thoroughly, before real students depend on it.

What we hold them to.

The standard every security and integrity partner has to meet before we bring them onto a campus system.

01

Genuine independence

No conflict of interest with the systems or teams being reviewed.

02

Current certifications

SOC 2, ISO 27001 and GDPR expertise kept active, protecting student and research data on paper and in practice.

03

Actionable findings

Reports our IT team can act on immediately, not a compliance checklist nobody reads.

04

Follow-through

Re-testing after fixes ship, so a finding actually gets closed, not just filed.

How the review runs.

Security and integrity review built into the academic calendar, not bolted on before exam season.

01

Scope

Risk model and data-protection requirements agreed before review starts on any student-facing system.

02

Test

Independent review of the portal, exam systems and research infrastructure against real threat scenarios.

03

Remediate

Findings triaged and fixed by the same team who built the system, with clear ownership.

04

Certify

Re-test and sign-off, with a report our own leadership and, where relevant, students can rely on.

What students should sleep on.

Confidence that isn't just internal reassurance.

Data protection should be something students can trust, not just something we tell them.

That means independent audit reports, clear remediation timelines, and data-handling documentation our own leadership can point to.

It also means we treat every finding as real, whether it came from our own team or a partner's, because a student's exposure doesn't care who found the gap.

For the rest of our partner network, see all partners or talk to us.

monolith

Hi there.

How can I help you today?