Antheon
    SupportNewsroomPolicy
    Sign in
    Sign in
    ← Trust & Policy

    Antheon Workspace Security Policy

    How identity, permissions, encryption, audit and incident response work across Antheon Workspace.

    Last updated · 1 May 2026Effective · 1 June 2026

    On this page

    01Security overview02Security governance03Data classification and handling04Access control and identity05Encryption06Infrastructure and hosting07Secure software development08Change management and release engineering09Logging, monitoring and detection10Incident response11Business continuity and disaster recovery12Vendor and sub-processor management13Personnel security14Physical and environmental security15Penetration testing and assurance16Responsible disclosure17Security contact

    Security overview

    The Antheon Company ("Antheon") operates Antheon Workspace as an information security-aware platform. This Security Policy describes the broad controls, processes and practices we use to protect customer data and the Service. It applies to Antheon Workspace and to the Antheon products available on it.

    We aim to align our practices with widely recognised information security frameworks, including the principles of the Australian Privacy Principles, the Australian Government's Essential Eight maturity model, and standards such as ISO/IEC 27001. Our specific controls evolve over time as the threat environment, the product and our customer base change.

    Security governance

    Security at Antheon is owned by the team that builds and runs the Service, with policies that are reviewed on a regular basis and updated when the product, the threat environment or the law materially changes. Material changes to security posture are communicated to Antheon personnel and, where relevant, to customers.

    We perform risk assessments on a regular cadence and whenever there is a significant change to the architecture, the legal landscape or the way customers use the Service.

    Data classification and handling

    We classify the data we hold according to its sensitivity and apply controls appropriate to each class. Broadly:

    • Restricted — student personal information, wellbeing inputs, authentication secrets, encryption keys and financial information. Restricted data is encrypted at rest and in transit, access is limited to the people who need it, and access events are logged.
    • Confidential — operational data, internal communications, source code and business records. Access is limited to people with a genuine need to know.
    • Internal — internal documentation, policies and procedures.
    • Public — marketing material and documentation that has been approved for public release.

    Data handling rules — including retention, transfer mechanisms and deletion — vary by classification.

    Access control and identity

    Customer-facing identity

    • Authentication options include single sign-on through commonly used identity providers, email-link sign-in, and passkeys.
    • Automated user provisioning is supported through SCIM where the School chooses to enable it.
    • Multi-factor authentication is supported and can be required by Schools as part of their configuration.
    • Standard protections such as login throttling, anomaly detection and account-lockout policies are applied to authentication paths.
    • Session lifetime, idle timeout and concurrent session limits can be configured by Schools where the feature is available.
    • Where passwords are used, they are stored using widely accepted password-hashing techniques.

    Internal and privileged access

    • Antheon staff use multi-factor authentication to access internal systems.
    • Access to production environments is granted on a least-privilege basis and is reviewed on a regular cadence.
    • Privileged actions in production are logged and attributable to a named individual.
    • Standing access to customer data is kept to a small group of staff with a legitimate need; access for support cases is granted on a just-in-time basis with appropriate approval.

    Encryption

    • Traffic between client devices and the Service is encrypted using current versions of TLS.
    • Inter-service traffic within our infrastructure is encrypted in transit.
    • Data at rest in production databases, object storage and backups is encrypted using strong, widely accepted algorithms.
    • Cryptographic keys are managed through reputable key management services and are rotated on a sensible cadence and whenever there is reasonable suspicion of compromise.
    • Mobile applications make use of operating-system facilities for secure credential storage.

    Infrastructure and hosting

    The Service is hosted on reputable cloud infrastructure providers whose physical and environmental controls are inherited by the Service. Production data for Australian customers is kept within Australia where reasonably practicable. Application workloads run in container orchestration platforms with appropriate isolation between workloads. Tenant data is segregated using tenant identifiers and database-level controls. Production environments are kept logically separate from non-production environments.

    Network protections include cloud-native firewalls, private subnets, web application firewalls and protection against common denial-of-service attacks.

    Secure software development

    We aim to build security into the way the Service is developed. Practices we follow include:

    • Code review and at least one approving reviewer for every change merged to production.
    • Automated checks for known-vulnerable dependencies and common security issues.
    • Application security testing in pre-production environments on a regular cadence.
    • Threat modelling for material architectural changes, with the resulting risks tracked to closure.
    • Security awareness training for staff who build and run the Service.

    Change management and release engineering

    Changes to production are deployed through automated pipelines. Every change is traceable to a pull request, an approving reviewer, the commit author and the deployment record. Deployments may be rolled back when health metrics indicate a regression.

    Database schema changes are managed through versioned migrations that are tested in non-production environments before release.

    Logging, monitoring and detection

    • Authentication events, administrative actions, configuration changes and material data access events are logged.
    • Logs are retained for a period appropriate to security and troubleshooting needs and are protected against tampering.
    • Automated detections and alerts route to an on-call rotation, with runbooks for the most common incident types.
    • We use synthetic monitoring, real-user monitoring and uptime probes to keep an eye on the Service.

    Incident response

    We operate a documented incident response process with severity-based triage and an on-call rotation. The process is exercised regularly.

    If an eligible data breach occurs, Antheon will:

    • Notify affected Schools without undue delay, in line with the Notifiable Data Breaches Scheme and any other breach notification laws that apply.
    • Provide enough information for affected Schools to meet their own notification obligations.
    • Cooperate with affected Schools, regulators and law enforcement.
    • Conduct a post-incident review with documented corrective and preventive actions.

    Business continuity and disaster recovery

    • Production data is backed up with point-in-time recovery for a reasonable rolling window.
    • Disaster recovery procedures are documented and exercised periodically.
    • Critical processes have basic business continuity plans, including supplier and personnel contingency planning.

    Specific recovery objectives that apply to your subscription, if any, are described in your service-level documentation.

    Vendor and sub-processor management

    We engage third-party providers to help us operate the Service. Providers that handle Restricted or Confidential data are required to enter into agreements that protect that data consistently with this Policy. We review these arrangements on a regular cadence and update them as needed.

    A current list of sub-processors is described in our Privacy Policy and is updated as the list changes.

    Personnel security

    • Antheon staff complete role-appropriate background checks before commencement where the role involves access to Restricted data.
    • All staff are bound by confidentiality obligations that survive termination.
    • Security awareness training is delivered on commencement and refreshed on a regular cadence.
    • Access is reviewed on a regular cadence and revoked promptly when no longer required.
    • Staff are encouraged to report security events through documented channels.

    Physical and environmental security

    Antheon does not operate its own production data centres. Production data is hosted with reputable cloud providers that operate to recognised data centre standards. Laptops and other devices used by Antheon staff are subject to standard endpoint security measures such as full-disk encryption, screen-lock requirements and remote-wipe capability.

    Penetration testing and assurance

    • We engage external testing of the Service on a periodic basis and act on the findings.
    • We welcome co-operative security research under a responsible-disclosure approach (see below).
    • We are happy to support reasonable customer-led security questionnaires under standard non-disclosure terms.

    Responsible disclosure

    If you believe you have identified a security vulnerability in the Service, please report it through the Antheon Support Center with a description of the issue, steps to reproduce it and (where possible) a suggested remediation. Do not access, modify or destroy any data, and do not perform any action that may impact other users while researching.

    Antheon will not pursue legal action against researchers who act in good faith, with reasonable care, and within the scope of these rules.

    Security contact

    For security-related enquiries, contact us through the Antheon Support Center.

    Questions about this policy?

    Procurement, legal, IT or compliance: send us a message and we’ll get back to you.

    Contact support →All policies →
    AntheonRequest a demo
    Platform
    WorkspaceStudioClassroomHealthEducatorGuardianCampusPayMeet
    Get started
    PricingRequest a demoLog inCreate account
    Resources
    Support centreNewsroomCourse centreBlogSystem statusCommunity board
    Legal
    Trust & PolicyPrivacyTermsSecurityPaymentsAI policyAccessibility
    © 2026 Antheon
    PrivacyTermsSecurityStatus