Trust

Trusted with the young people who need it most.

Safeguarding and data protection are built in as a benefit, not bolted on as a checklist.

The standard a system holding this data should meet, met quietly.

Safe by design

Safe by design, from the first line of code.

The young people in an alternative provision are among the most vulnerable anywhere in the system. A platform that holds their information has to earn the right to.

So safeguarding, accountability and data protection were not features added late. They shaped how the platform was built, and they run through every part of it.

Safeguarding

Accountable for every young person, and every action.

Risk assessment and a full audit trail run through the platform.

Every change is recorded. Every monthly report is reviewed by a person and signed off by a leader before it goes anywhere. The platform shows who did what, and when. Nothing important happens without a trail behind it. That includes the portal: when a commissioner or a school views a placement, the view is logged by name and time.

For your safeguarding lead

Built to a DSL's standards.

The things a safeguarding lead checks for are not extras here. They are how the platform works.

Versioned risk assessments, with the full history chain keptA notes timeline with pinned authorship, so a record cannot be quietly rewrittenA DSL role with all-areas safeguarding authority, enforced by the platformA consent and medical engine, so permissions and needs are recorded, not rememberedEvery portal view by a commissioner or school, logged by name and time
Rebecca Freeman
As a DSL I can see every change, every sign-off, and who viewed what, with a name and a time against all of it. And my mentors walk into a first session already knowing what helps that young person. That is the difference.
Rebecca Freeman, MD and DSL, Illuminate AP
Access

The right people see the right things.

Role-based access across nine roles, scoped by area and site.

A mentor sees the young people they work with. A leader sees the sites they are responsible for. Access follows the job, so sensitive information is only ever in front of the people who need it. Sign-in is multi-factor.

Isolation

Your data, provably yours alone.

Every provision's data is isolated from every other's, and we do not take that on trust. The platform continuously runs automated cross-tenant drills against its own database, hundreds of read, write, delete and insert checks, attempting exactly what an attacker would attempt and proving it fails. A drift detector compares live permissions against a signed-off baseline, so a change that widens access is caught, not discovered. This is our own automated regime, run continuously, not an annual box tick.

Data protection

Built to UK data protection, not retrofitted to it.

The platform is built around UK data protection law, and data minimisation is the default.

Information is held because it helps a young person move forward, not gathered for its own sake. Each setting remains the data controller; Hapio acts as the data processor, only on your instructions. The platform's data is hosted in the United Kingdom, in London.

AI, done right

AI narrates. It never decides.

The platform uses AI to draft the words of a monthly report, and nothing more.

Every number, score, level and recommendation is calculated by the platform and is fully auditable. AI only turns recorded evidence into readable prose. A person reviews and edits it, and a leader signs it off, before it is shared. Before any of a young person's data reaches an AI model it is anonymised, and it is not used to train one.

At a glance

What that means in practice.

Anonymised before AI

A young person's data is anonymised before it reaches any AI model, and never used to train one.

Role-based access

Nine roles, scoped by area and site, so people see only what their job needs.

Full audit trail

Every change and sign-off is recorded, with a person and a leader behind every report.

Multi-factor sign-in

Access to the platform is protected by multi-factor authentication.

UK data protection

Built around UK data protection law, hosted in the United Kingdom, with data minimisation as the default.

Human sign-off

AI drafts the prose, a person reviews, and a leader signs off before anything is shared.

Encrypted, in transit and at rest

Information is encrypted while it moves and while it is stored.

Tested against itself, continuously

The platform runs automated drills against its own database, hundreds of checks that one setting's data can never be seen from another, with any drift from the signed-off baseline flagged.

Where your data lives

No mystery about who touches your data.

We work with a small number of trusted providers to host the platform, draft report prose, and send our emails. We will share the full list, and a data processing agreement, with any setting that asks. Hosting is in the United Kingdom, in London.

We are registered with the ICO, registration ZC220766. A full list of sub-processors is available on request, and we are happy to complete a setting's own due-diligence and security questionnaires.

The young people come first. So does protecting them.

Book a demo and we will walk you through every safeguard, in plain terms.

Read our data protection summary