Safeguarding and governance

Governance-first AI for education.

Curious Minds Lab is designed with teacher oversight, moderation workflows, safeguarding systems, GDPR alignment, audit logging, and school procurement readiness from the beginning. AI supports the learning experience while teachers remain in control of what is created, reviewed, approved, and published.

AAL2 MFA

Live

TOTP second-factor authentication enforced for all admin and organisation roles. Teachers and students are unaffected.

Row-level security

Live

Supabase RLS policies restrict every database table to the minimum required access for each role. No role can read data outside its scope.

EU-hosted data

Live

All data stored in EU-region infrastructure. No transatlantic transfers for student records or personally identifiable information.

GDPR aligned

Live

Pseudonymous students — no real names, DOBs, or email addresses collected. Data minimisation built in from the first line of code.

Accessibility review

In progress

SEND and accessibility testing is part of the pilot, including reading support needs and future speech-to-text planning before broader rollout.

ICO Children's Code

In progress

Age-appropriate design review and ICO Children's Code alignment are in place. ACCS-3 certification is pending.

DPIA

Available

DPIA documentation is available on request. It has been reviewed for the controlled pilot, with wider rollout subject to final school and supplier readiness checks.

Design principles

Built for school procurement from day one.

Teacher authority

No AI-generated content reaches a student without a teacher reviewing and approving it first. The teacher is always the final decision-maker.

Reject and revise

If a mission is not approved, it remains unavailable to students. Teachers can edit, reject, remove, regenerate, or escalate concerns before any later approval.

Pseudonymous students

Students are identified only by a display name and a random code. No real names, dates of birth, or contact details are ever collected or stored.

Audit trail

Every moderation action — approval, rejection, edit, removal — is logged against a teacher identity and timestamp for accountability and review.

Questions about procurement or compliance?

We are happy to share documentation, answer DPO questions, and discuss how CML fits your school's safeguarding requirements.

Get in touch