Security overview
The Antheon Company ("Antheon") operates Antheon Workspace as an information security-aware platform. This Security Policy describes the broad controls, processes and practices we use to protect customer data and the Service. It applies to Antheon Workspace and to the Antheon products available on it.
We aim to align our practices with widely recognised information security frameworks, including the principles of the Australian Privacy Principles, the Australian Government's Essential Eight maturity model, and standards such as ISO/IEC 27001. Our specific controls evolve over time as the threat environment, the product and our customer base change.
Security governance
Security at Antheon is owned by the team that builds and runs the Service, with policies that are reviewed on a regular basis and updated when the product, the threat environment or the law materially changes. Material changes to security posture are communicated to Antheon personnel and, where relevant, to customers.
We perform risk assessments on a regular cadence and whenever there is a significant change to the architecture, the legal landscape or the way customers use the Service.
Data classification and handling
We classify the data we hold according to its sensitivity and apply controls appropriate to each class. Broadly:
- Restricted — student personal information, wellbeing inputs, authentication secrets, encryption keys and financial information. Restricted data is encrypted at rest and in transit, access is limited to the people who need it, and access events are logged.
- Confidential — operational data, internal communications, source code and business records. Access is limited to people with a genuine need to know.
- Internal — internal documentation, policies and procedures.
- Public — marketing material and documentation that has been approved for public release.
Data handling rules — including retention, transfer mechanisms and deletion — vary by classification.
Access control and identity
Customer-facing identity
- Authentication options include single sign-on through commonly used identity providers, email-link sign-in, and passkeys.
- Automated user provisioning is supported through SCIM where the School chooses to enable it.
- Multi-factor authentication is supported and can be required by Schools as part of their configuration.
- Standard protections such as login throttling, anomaly detection and account-lockout policies are applied to authentication paths.
- Session lifetime, idle timeout and concurrent session limits can be configured by Schools where the feature is available.
- Where passwords are used, they are stored using widely accepted password-hashing techniques.
Internal and privileged access
- Antheon staff use multi-factor authentication to access internal systems.
- Access to production environments is granted on a least-privilege basis and is reviewed on a regular cadence.
- Privileged actions in production are logged and attributable to a named individual.
- Standing access to customer data is kept to a small group of staff with a legitimate need; access for support cases is granted on a just-in-time basis with appropriate approval.
Encryption
- Traffic between client devices and the Service is encrypted using current versions of TLS.
- Inter-service traffic within our infrastructure is encrypted in transit.
- Data at rest in production databases, object storage and backups is encrypted using strong, widely accepted algorithms.
- Cryptographic keys are managed through reputable key management services and are rotated on a sensible cadence and whenever there is reasonable suspicion of compromise.
- Mobile applications make use of operating-system facilities for secure credential storage.
Infrastructure and hosting
The Service is hosted on reputable cloud infrastructure providers whose physical and environmental controls are inherited by the Service. Production data for Australian customers is kept within Australia where reasonably practicable. Application workloads run in container orchestration platforms with appropriate isolation between workloads. Tenant data is segregated using tenant identifiers and database-level controls. Production environments are kept logically separate from non-production environments.
Network protections include cloud-native firewalls, private subnets, web application firewalls and protection against common denial-of-service attacks.
Secure software development
We aim to build security into the way the Service is developed. Practices we follow include:
- Code review and at least one approving reviewer for every change merged to production.
- Automated checks for known-vulnerable dependencies and common security issues.
- Application security testing in pre-production environments on a regular cadence.
- Threat modelling for material architectural changes, with the resulting risks tracked to closure.
- Security awareness training for staff who build and run the Service.
Change management and release engineering
Changes to production are deployed through automated pipelines. Every change is traceable to a pull request, an approving reviewer, the commit author and the deployment record. Deployments may be rolled back when health metrics indicate a regression.
Database schema changes are managed through versioned migrations that are tested in non-production environments before release.
Logging, monitoring and detection
- Authentication events, administrative actions, configuration changes and material data access events are logged.
- Logs are retained for a period appropriate to security and troubleshooting needs and are protected against tampering.
- Automated detections and alerts route to an on-call rotation, with runbooks for the most common incident types.
- We use synthetic monitoring, real-user monitoring and uptime probes to keep an eye on the Service.
Incident response
We operate a documented incident response process with severity-based triage and an on-call rotation. The process is exercised regularly.
If an eligible data breach occurs, Antheon will:
- Notify affected Schools without undue delay, in line with the Notifiable Data Breaches Scheme and any other breach notification laws that apply.
- Provide enough information for affected Schools to meet their own notification obligations.
- Cooperate with affected Schools, regulators and law enforcement.
- Conduct a post-incident review with documented corrective and preventive actions.
Business continuity and disaster recovery
- Production data is backed up with point-in-time recovery for a reasonable rolling window.
- Disaster recovery procedures are documented and exercised periodically.
- Critical processes have basic business continuity plans, including supplier and personnel contingency planning.
Specific recovery objectives that apply to your subscription, if any, are described in your service-level documentation.
Vendor and sub-processor management
We engage third-party providers to help us operate the Service. Providers that handle Restricted or Confidential data are required to enter into agreements that protect that data consistently with this Policy. We review these arrangements on a regular cadence and update them as needed.
A current list of sub-processors is described in our Privacy Policy and is updated as the list changes.
Personnel security
- Antheon staff complete role-appropriate background checks before commencement where the role involves access to Restricted data.
- All staff are bound by confidentiality obligations that survive termination.
- Security awareness training is delivered on commencement and refreshed on a regular cadence.
- Access is reviewed on a regular cadence and revoked promptly when no longer required.
- Staff are encouraged to report security events through documented channels.
Physical and environmental security
Antheon does not operate its own production data centres. Production data is hosted with reputable cloud providers that operate to recognised data centre standards. Laptops and other devices used by Antheon staff are subject to standard endpoint security measures such as full-disk encryption, screen-lock requirements and remote-wipe capability.
Penetration testing and assurance
- We engage external testing of the Service on a periodic basis and act on the findings.
- We welcome co-operative security research under a responsible-disclosure approach (see below).
- We are happy to support reasonable customer-led security questionnaires under standard non-disclosure terms.
Responsible disclosure
If you believe you have identified a security vulnerability in the Service, please report it through the Antheon Support Center with a description of the issue, steps to reproduce it and (where possible) a suggested remediation. Do not access, modify or destroy any data, and do not perform any action that may impact other users while researching.
Antheon will not pursue legal action against researchers who act in good faith, with reasonable care, and within the scope of these rules.
Security contact
For security-related enquiries, contact us through the Antheon Support Center.
