Trust & security
Your students’ data, handled carefully
Enrolmate holds sensitive information: passports, academic records, financial evidence. Protecting it is part of the product, not an afterthought. This page describes what we actually do, in plain language.
NZ data residency
Student data is stored and processed in New Zealand, under New Zealand law.
Encrypted, twice
TLS in transit, encryption at rest, plus field-level AES-256-GCM on passport and national student numbers.
Two-factor auth
TOTP 2FA with recovery codes. Organisations can require it for every staff member.
Privacy rights built in
Data export and erasure for individuals are product features, not support tickets.
Disaster recovery
Daily encrypted backups and document replicas held in a geographically separate location.
Audited access
Sensitive actions are logged. Support access is time-boxed, visibly bannered, and audited.
Where your data lives
Production runs on enterprise cloud infrastructure in New Zealand: student data is stored and processed on New Zealand soil, under New Zealand law. For disaster recovery, encrypted backups and document replicas are also held in Australia. Data is encrypted in transit (TLS) and at rest. We do not sell data, and we do not use student records to train AI models.
Encryption beyond the baseline
Everything is encrypted at rest, and the most sensitive identity fields (passport numbers and national student numbers) carry a second layer of field-level AES-256-GCM encryption, so even a database-level exposure would not reveal them in usable form. Two-factor secrets are protected the same way.
Accounts & access
- Two-factor authentication. TOTP-based 2FA with single-use recovery codes. A provider can require 2FA for every member of their organisation.
- Scoped by organisation. A provider only ever sees applications submitted to that provider, enforced on the server, never by hiding buttons.
- Scoped by role. Owner, admin, staff and read-only levels within a provider; agents and advisers see only their own caseload.
- Student consent. Students choose which providers and advisers can see their file and can revoke access.
- Audit trail. Sensitive actions are logged with who and when. When our support team assists inside an account, the session is time-boxed to 30 minutes, shows a visible banner, and is bracketed in the audit log.
- Consent-first support. Helpdesk staff can only enter your account after you approve the request, and can only see your screen when you click share. You can end either with one click, and nothing is ever recorded.
- Passwords are hashed with a modern algorithm; sessions are signed, HTTP-only, and expire.
Availability & recovery
- Zero-downtime deploys. New versions roll out alongside the old, and a failing release rolls back automatically.
- Backups. Daily encrypted database backups with multi-week retention, copied to a second region, with documented restore procedures we actually rehearse.
- Post-deploy verification. Every production release ends with automated checks against the live service.
Your rights under the Privacy Act 2020
You can ask to see the information we hold about you, have it corrected, or have it deleted when it is no longer needed. Export and erasure are built into the platform, so requests are actioned quickly rather than queued behind engineering work. See the privacy policy for detail.
Our compliance programme
We maintain a privacy impact assessment, a record of processing activities, and an incident response plan that includes notification to the Office of the Privacy Commissioner where a breach threshold is met. Our security controls are mapped against ISO/IEC 27001, and independent certification is on our roadmap. Procurement teams can request our documentation pack, including our sub-processor list, by emailing us.
Sub-processors
We keep the list short: Amazon Web Services (hosting, NZ and AU regions), Resend (transactional email), and Anthropic (document-verification AI; customer data is not used for model training). Full details are in our data processing documentation, available on request.
Reporting a vulnerability
If you believe you’ve found a security issue, please tell us before disclosing it publicly. Email security@enrolmate.io with enough detail to reproduce it. We’ll acknowledge within one business day, keep you updated, and we won’t pursue researchers who act in good faith.