🎓 Schools & education

A school carries duties from several directions at once: privacy law that differs depending on whether it is government or non-government, a state education department policy, registration conditions, child-safety standards, and a long tail of EdTech apps holding student data. Most of the guidance a school finds online is written for the wrong sector or the wrong state, so schools either over-comply with rules that do not bind them or miss the ones that do.

Book a demo → Try it on sample docs
Tier-A breadthStudent privacy · Essential Eight · child safety · EdTech vendors

Running more than one school?

A single school is $4,503 / school / year (or $395 / school / month billed monthly). Do not multiply that out. From 3 schools it becomes a different conversation — volume pricing, one group administrator, and consolidated posture across every site with each site still gated to its own jurisdiction, because a provider operating in more than one state genuinely carries different duties per school.

Multi-school pricing is quoted by sales — email sales@cybersentien.com. We do not publish a per-school rate for groups, because the right number depends on how many sites you run and which states they are in — and a figure invented on a web page is not a quote we could stand behind.
Contact sales → See pricing
All subscriptions are prepaid. Your access period starts the day you pay and runs ~30 days on monthly billing, or a year on annual. Cancel any time — cancelling stops the next charge and you keep full access until the end of the period you have already paid for, not the moment you click. A refund ends access immediately.

Frameworks on the engine serving this vertical

Read from the live catalogue at build time — a framework that is not live on the engine never renders here. Depth is badged per framework: consultant-grade only where we go deepest (ISM/IRAP, Essential Eight), Tier-A breadth everywhere else.

Licence-gated catalogues carry control IDs and CyberSentien's own labels only — the full standard text requires your licence and is never reproduced.

Depth today — stated honestly

Tier-A breadth: 195 curated obligations, each traced to a named primary source — legislation, regulator, education department or registration authority — and each stating the SECTOR (government vs non-government) and JURISDICTION it binds. That matters: the federal Privacy Act does not cover government schools, which fall under state privacy law instead, so an obligation shown without its scope would be a duty your school may not actually have. Honest about depth: every theme is now covered in every state and territory — governance, student privacy, cyber controls, incident and breach, child safety (including reportable-conduct schemes, mandatory reporting and working-with-children screening) and EdTech/records. It also covers the privacy artefacts a school must produce, not just the duties it must observe — the NSW Privacy Management Plan, the Victorian PDSP and annual VPDSS control report, and the breach-response policies WA and Queensland require agencies to publish. Depth is still greatest for Victoria and NSW. Two findings are recorded as honest negatives rather than padded: the Northern Territory has no publicly verifiable school-binding cyber standard and no TERRITORY-level mandatory breach-notification scheme — NT non-government schools remain covered by the federal NDB scheme as private-sector APP entities. Essential Eight is assessed across ML1–ML3 on real artefacts. Where an obligation is not covered, the posture says so instead of shading it green.

See it on the real engine

Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.

Request the demo →Try it now →