Security & privacy
Built to pass the IT committee.
Lantern keeps every student name and report comment onshore, encrypted and audited. Your data is never used to train AI models. Here is exactly how, in plain language.
01 · Data sovereignty
Your students’ data never leaves Australia.
Storage, backups, processing and AI inference all run inside Australian AWS regions. The primary region is Sydney; if Sydney becomes unavailable, we fail over to Melbourne. Nothing is replicated, cached or processed offshore. There is no cross-border disclosure to assess.
- Primary region: AWS Sydney (ap-southeast-2)all live data
- Disaster recovery: AWS Melbourne (ap-southeast-4)cross-region DR
- AI inference pinned to Australian regionsno offshore brokers
The legal entity behind Lantern is [PLACEHOLDER: registered entity, e.g. Ember Education Pty Ltd], ABN [PLACEHOLDER: 11-digit ABN], ACN [PLACEHOLDER: 9-digit ACN], an Australian company hosting on Australian soil.
02 · How we protect it
Encrypted, access-controlled and fully audited.
Every layer is locked down by default: the network, the database, the backups and the people who can touch them. The controls below are the ones a security reviewer will ask about first.
- Hosted in Sydney
- All student and report data lives in AWS Sydney (ap-southeast-2), with disaster recovery in Melbourne (ap-southeast-4). Data is never stored or processed offshore.
- AI runs onshore
- Drafting and compliance checking run on enterprise AI infrastructure pinned to Australian regions. Prompts are not routed through overseas brokers.
- Never used to train models
- Your reports, student notes and prompts are never used to train, fine-tune or improve any AI model, and prompts are not retained by the model provider. This is a contractual commitment, not a setting.
- Encrypted end to end
- TLS 1.2+ for everything in transit; AES-256 at rest for the database, backups and object storage. Encryption keys are managed in AWS KMS.
- Least-privilege access
- Every query is scoped to the signed-in user's school. Staff access is role-based, multi-factor and granted on a need-to-know basis, with production access reviewed regularly.
- Immutable audit trail
- An append-only audit log records who viewed, drafted, edited, approved and exported what, and when. It cannot be altered after the fact.
- No student accounts
- Students never log in and have no profiles. They exist only as names on their teacher's class roster. There is no student-facing surface to attack.
- 30-day deletion
- When a school leaves or requests erasure, data is soft-deleted immediately and permanently purged from primary stores and backups within 30 days.
03 · No training on your data
Your reports are never training data.
Lantern learns each teacher’s voice only within their own school’s workspace, to draft that teacher’s comments. It never feeds a shared or external model. Student notes, report drafts and the prompts we send to the AI are never used to train, fine-tune or improve any model, and are not retained by the model provider after a request completes. This is written into our contracts and our sub-processor agreements, so it cannot quietly change.
For schools that want it, our de-identified writing corpus, used to improve Lantern’s style and compliance features, strips all student-identifying information before anything is retained, and never includes a school’s data without that step.
Not ready for AI drafting at all? Schools can run Lantern as a compliance checker only: comments in, findings out, no generation.
04 · Privacy by design
Aligned to the Australian Privacy Principles.
Privacy isn’t a policy bolted on at the end. It shapes how Lantern is built. Here is how our controls map to the Australian Privacy Principles that govern how your school’s information is handled.
- APP 1 · Open and transparent
- A plain-language privacy policy, this security overview, and a Data Processing Agreement set out exactly what we collect and why.
- APP 3 & 5 · Collection
- Lantern collects only what a teacher needs to draft a comment: a student's name and the teacher's own notes. The school remains the data controller; we are a processor acting on its instructions.
- APP 6 · Use and disclosure
- Data is used solely to provide the service to your school. It is never sold, shared for advertising, or used to train AI models.
- APP 8 · Cross-border disclosure
- There is no cross-border disclosure: storage, processing and AI inference all stay within Australia.
- APP 11 · Security
- Encryption, least-privilege access, audit logging and a documented breach-response process protect the information we hold.
- APP 12 & 13 · Access and correction
- Schools can request access to, correction of, or erasure of their data through a documented workflow inside the product.
The full detail lives in our privacy policy, and the contractual commitments, including processing terms and breach obligations, are set out in our Data Processing Agreement.
05 · When something goes wrong
A clear breach-response process.
We hope never to use it, but we maintain a documented incident- and breach-response process aligned to the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If an eligible data breach is likely to result in serious harm, we will:
- Contain and assess the incident promptlywithin hours
- Notify affected schools without undue delay, as data controllersyou decide next steps
- Support notification to the OAIC and affected individuals where requiredNDB scheme
- Run a post-incident review and remediate root causesevery time
Security questions or to report a concern, contact security@embereducation.com.au.
06 · AI governance
Responsible AI, by design.
Lantern’s use of AI is governed in line with Australia’s Voluntary AI Safety Standard (2024). The teacher is always the author and approver. Lantern drafts and checks, but never publishes a comment on its own.
- Human accountability: the teacher approves every commentnever auto-published
- Transparency: drafts are clearly AI-assisted; edits flaggednever silently rewritten
- Testing & monitoring of model quality and safetyongoing
- Records that let you contest and trace an AI-assisted draftimmutable audit log
Because every action is recorded in the immutable audit trail, a school can always see where AI was involved in a comment and who signed off on the final wording.
For procurement and IT reviewers.
The controls behind the claims, ready for assessment.
We are ready to complete State and Territory education-department vendor security assessments and questionnaires. Our Data Processing Agreement covers processing terms, sub-processors and breach obligations; see our current sub-processors and privacy policy.
Bring us your toughest security questionnaire.
School leaders and IT teams: we’ll walk your reviewers through the architecture, the audit trail and the DPA, and answer the questions your assessment template asks.