4P3X SafeSpark™ logo 4P3X SafeSpark™Education support platform

Production-readiness roadmap

Security and Data Protection Roadmap

The technical, organisational and child-focused controls required before real school deployment.

Roadmap status

This page describes production requirements, not completed certification. The public build demonstrates product flows but must not be treated as a secure repository for real pupil or safeguarding information.

Production security and data-protection requirements

Required before production

Encryption

Encrypt data in transit and at rest using managed keys, documented rotation and secure secret handling.

Required before production

Authentication

Use secure school-controlled identity, multi-factor protection for privileged roles and safe account recovery.

Required before production

Role-based access control

Apply least privilege, role separation, authorisation checks and periodic access review.

Required before production

Audit logs

Record meaningful security and data actions with tamper resistance, restricted access and defined retention.

Required before production

Secure backups

Use encrypted, tested backups with recovery objectives, restoration exercises and separation from production.

Required before production

Incident response

Maintain detection, triage, containment, notification, recovery and lessons-learned procedures.

Required before production

Penetration testing

Commission independent testing before production and after material architectural changes.

Required before production

Vulnerability management

Track dependencies, scan regularly, prioritise remediation, patch promptly and disclose material risk responsibly.

Required before production

Data-processing agreements

Document controller/processor roles, sub-processors, international transfers, security duties and deletion on exit.

Required before production

Retention and deletion controls

Apply purpose-based schedules, legal holds where necessary, verified deletion and school-controlled export/offboarding.

Required before production

Child-focused DPIA

Assess necessity, proportionality, children’s best interests, special-category risks, mitigations and residual risk.

Required before production

ICO Children’s Code

Assess whether the service is likely to be accessed by children and build applicable age-appropriate design standards into the product.

Assurance gates before a live pilot

  1. Define the production architecture, data flows, controller/processor roles and information classification.
  2. Complete threat modelling, safeguarding review, DPIA and Children’s Code assessment where applicable.
  3. Implement and document the required technical and organisational controls.
  4. Complete secure-code review, vulnerability testing, penetration testing, recovery testing and accessibility testing.
  5. Resolve critical and high-risk findings or formally document justified treatment and accountable acceptance.
  6. Approve school contracts, privacy information, retention schedules, incident routes, support arrangements and staff training.
  7. Run a limited, monitored pilot with fictional or minimised data before expanding scope.

Ongoing production duties

Security and data protection are continuing processes. A live service would need patching, monitoring, access reviews, staff training, supplier assurance, incident exercises, backup tests, policy reviews, DPIA updates and evidence that controls continue to operate as intended.

Current architecture

Local-first demonstration architecture

Local and offline storage

Demonstration preferences, fictional progress and lesson availability can remain on the device through browser storage and service-worker caches.

Role boundaries

All ten SafeSpark™ role environments have separate purposes and permission boundaries. Production identity and authorisation controls remain required.

Data minimisation

The public version should use fictional data only and collect no more information than is needed to demonstrate a workflow.

Controlled export and import

File and handoff demonstrations illustrate deliberate movement of information rather than unrestricted background sharing.

Optional future synchronisation

Remote synchronisation is a future production option, not a claim that the public build currently sends pupil records to a central service.

Audit concepts

Demonstration audit trails show intended accountability. Production logs would require tamper resistance, access controls, retention rules and review procedures.

Current limitation: formal penetration testing, certification and production security approval have not been completed. Production requires authentication, encryption review, independent penetration testing, DPIA, retention rules and incident-response planning.

Contact and feedback

Report an accessibility problem, privacy concern, safeguarding wording issue or other problem to the SafeSpark™ operator. Do not include real pupil records or safeguarding disclosures in a public-demo enquiry.