Encrypted web access
Pastoral Hub is served over HTTPS. The service uses HTTP Strict Transport Security so supported browsers continue to use encrypted connections.
Approved staff access
Protected school workspaces require approved authentication. Access is not granted simply because someone knows a workspace URL.
Permission boundaries
Access can be limited by staff role, year level and operational responsibility. Sensitive actions are checked at the server boundary, not only hidden in the interface.
No public student records
The public Pastoral Hub website contains no student records, pastoral notes, attendance data, behaviour information or academic results.
Security headers
Pastoral Hub uses controls including HSTS, frame protection, MIME-type protection, a restrictive permissions policy and a Content Security Policy to reduce common browser-based risks.
Separate workspaces
School workspaces are separated from the public website. School administrators control approved users and role assignments for their environment.
Security reporting
If you believe you have found a security issue, do not include student information, credentials or sensitive school data in an initial report. Use the service administrator or school contact responsible for your Pastoral Hub workspace. Automated security-disclosure information is published at: