Security & trust
Last updated 12 July 2026
Ceidwad is a cyber-security platform, so we hold ourselves to the standard we help schools reach. This page explains, in plain English, how we protect your data, what we can and can't see, and — importantly — how to tell a genuine message from us apart from a scam.
Connecting or reconnecting a system only ever happens inside your Ceidwad account, after you have signed in yourself. If you receive an email, text or call claiming to be from Ceidwad and asking you to "re-approve", "re-verify" or "renew" a connection by following a link, treat it as a scam. Don't click it — log in directly at ceidwad.co.uk or contact us using a route you already trust.
How to know a request is genuinely from us
- We only start a connection from inside the app, once you're logged in — never from a link we email or message you.
- Our emails come from an @ceidwad.co.uk address. We'll never send you to a look-alike domain, and we'll never ask for your Microsoft or Google password — you sign in with the provider directly, not through us.
- We'll never ask for payment details by email, or pressure you to act "within the hour". Genuine renewals are handled on an annual invoice, calmly and in writing.
- If anything looks off, stop and check. Go to ceidwad.co.uk yourself, or email hello@ceidwad.co.uk — we'd far rather you asked.
What Ceidwad can — and can't — see
Ceidwad reads your security posture: configuration and security signals such as whether multi-factor sign-in is on, whether devices are up to date, and how your settings compare to good practice. That is all we need to score your readiness and explain what to fix.
- Read-only. Connections are read-only by design — Ceidwad reports what it finds and prepares fixes for you to approve, but doesn't change your settings on its own.
- Never message content or files. We do not read emails, documents, calendars or chats.
- No MIS, message content or files. Ceidwad does not connect to your MIS and does not read emails, documents, calendars or chats. Where needed to provide the service, Ceidwad may process limited account and security identifiers such as usernames, display names, email addresses, device or account names, and security posture signals. Level 2 named detail is off by default and only enabled with customer authorisation. Pupils are not targeted by phishing simulations.
- You stay in control. You can see every connection in your account and remove any of them at any time.
AI transparency
Where Ask Ceidwad is enabled, we use Azure OpenAI to help turn security posture and incident information into plain-English explanations. The AI does not make decisions about individuals. Scores are calculated in code from measured security facts; the AI explains them.
Before relevant text is sent to Azure OpenAI, Ceidwad applies redaction and tokenisation controls designed to reduce direct identifiers such as email addresses, phone numbers, postcodes, IP addresses and user principal names. Free-text names may not always be detected. Azure OpenAI is not used to train Microsoft or third-party models on customer data. Our Privacy Policy sets out where this processing happens and the safeguards that apply.
How we protect your data
- Core platform data at rest is hosted in the UK. Ceidwad's core platform data is hosted in Microsoft Azure UK South where applicable. Some third-party services, including AI or identity-related services where enabled, may involve processing outside the UK under appropriate contractual safeguards, as described in our Privacy Policy and Data Processing Agreement.
- Encrypted in transit and at rest, with a separate encryption key for each school — so one school's data is cryptographically isolated from another's.
- Least data, least access. We hold only what we need to assess your posture, and access is limited and logged.
- No unearned badges. We won't display certifications we don't genuinely hold. Where we align to a framework (NCSC, the DfE digital standards, Cyber Essentials, RPA cyber-cover conditions), we say so as a statement of alignment — not a certification.
Reporting something suspicious
If you receive a message you think is impersonating Ceidwad, or you spot a security issue in the platform itself, please tell us at security@ceidwad.co.uk. Include as much detail as you safely can (for a suspicious email, the sender address and — without clicking anything — a screenshot). We investigate every report and will always thank you for it. Responsible disclosure is welcome. We will not pursue good-faith security research where it is lawful, avoids privacy harm, avoids unnecessary access to data, does not degrade or disrupt the service, and is reported promptly to security@ceidwad.co.uk.
A note for schools that outsource IT
If a managed IT provider (MSP) looks after your systems, the authority still sits with the school. A genuine connection is a one-time, read-only approval that you or your provider make from inside your own Ceidwad account — it never comes as an email link, and you can review or remove it yourself at any time. If your provider is ever asked to "re-approve Ceidwad" by email, that's a red flag worth checking with us first.