Journey

Trust & security

Trust information for regulated learner data

Journey is designed for records that may include special-category data, funding evidence and audit history. Its product controls, documented boundaries and current assurance evidence can be reviewed during procurement.

Evidence for procurement review

Journey documents relevant controls and provides current, scope-specific assurance evidence during procurement where applicable. Do not rely on this page as a certification register.

Access and audit controls

  • Provider-scoped accessTenant-scoped access checks apply within the authorised workspace
  • Attributable historySignificant actions are recorded against the person

Review the current control evidence for your proposed Journey scope during procurement.

Documents for your review

  • Security informationCurrent controls and operating boundaries
  • Data processingSubprocessors, privacy and agreed terms

We share scope-specific assurance evidence so your team can complete its own checks.

How we protect your data

Security is built into the architecture, not bolted on. These are the controls designed to protect provider data.

Tenant-scoped access controls

Journey uses server-side tenant context and active-membership, permission and record-scope checks in its implemented access controls. Scope-specific evidence is available during procurement where applicable.

Role-based access control

Permissions are catalogue-defined and granted per role. Access is limited according to role permissions, with sensitive PII gated behind specific permissions.

Controlled audit history

Significant application actions record who did what and when. Routine application paths do not edit audit entries; authorised retention or erasure operations are separately controlled and audited.

Documented hosting & encryption

Journey documents relevant hosting, encryption and approved sub-processor information in its current procurement materials and register. Scope-specific evidence is supplied during procurement where applicable.

Governed AI

Journey Advanced AI is tenant-aware and metered. It prepares authorised drafts and K/S suggestions for human review; regulated decisions, behaviour verification and record changes remain with authorised people. If a model is unavailable, the record remains unchanged.

Versioned funding controls

Funding, gateway, EPA and ILR checks run server-side against versioned rules. Journey provides explainable controls and audit evidence; the provider remains responsible for submission and regulatory decisions.

Policies & documents

Everything we publish, in one place. Need a signed DPA, a security questionnaire completed or evidence for your due diligence? Contact us to confirm the applicable scope and available documentation.