Thesis SM Security Features
How we secure Thesis SM
Thesis SM is a cloud-hosted Student Information System operated by Thesis Systems UK Limited. This page summarises the security controls protecting the platform and the operations behind it. The full Security Features document, together with the underlying policies of our Information Security Management System, remains the authoritative source and is available to customers and prospective customers for due diligence.
Certified Independently
Thesis SM operates within an Information Security Management System certified to ISO 27001:2022 by NQA, a UKAS-accredited certification body, with certification scoped to the development, provision and support of Student Information System software. The platform is hosted exclusively on Microsoft Azure, so customers also inherit Azure's certifications for their region, including ISO 27001, 27017 and 27018, ISO 22301, SOC 1, 2 and 3, and UK Cyber Essentials Plus.
Accountability sits with leadership: the Senior Director of IT & Information Security owns the ISMS, and risks are managed to ISO 27001 within a defined risk appetite, with intolerable risks always escalated for leadership review.
Customer data is provisioned into the Azure region matching your geopolitical zone, and processing, storage and backup stay within it. Each customer gets a separate database instance rather than a partition of a shared one.
Data in transit is encrypted with TLS 1.2 or higher; data at rest with AES-256, at both database and storage layers. Keys live in Azure Key Vault under least-privilege access, and secrets are never embedded in source code or pipelines. Personal data, student records, payment and authentication data are classified Restricted, with enforced multi-factor authentication and audit logging. On contract termination, data is returned in a migration-capable format or destroyed without retention, using cryptographic erasure.
Access is governed by role-based access control and least privilege, with MFA enforced for remote and privileged access. Sessions lock after five minutes of inactivity, accounts lock after five failed attempts, and inactive accounts are disabled after ninety days. You configure and manage your own application access; back-end access by Thesis personnel is limited to what support and maintenance require, and is centrally logged, with privileged activity logs retained for at least 90 days.
Development follows secure coding practices aligned to OWASP Top 10, with mandatory peer review on every change and Static Application Security Testing in controlled CI/CD pipelines. Production data is never used in development or QA unless anonymised and customer-approved. No release ships with unresolved Critical or High vulnerabilities without formal, leadership-approved risk acceptance, and independent penetration testing runs at least annually, with out-of-cycle testing after material change.
Production changes go through a formal process aligned to ISO 27001 and ITIL v4, with Change Advisory Board approval, rollback plans and predictable change windows; anything outside those windows is communicated in advance.
Incident response is aligned to ISO 27001, ISO 27035, NIST SP 800-61 and UK GDPR Articles 33 and 34. If a security incident is confirmed to affect your data, we notify you without undue delay, and in any event within 48 hours, then share timeline, scope, root cause and impact as they become known, so your institution, as controller, can make its own regulatory notification decisions with proper evidence.
RESILIENCE
Backups run exclusively within your designated Azure region, with point-in-time restoration inside the contractual recovery window. Disaster recovery is exercised through a full application-level test at least annually, with results available to customers on request. Contractual RTO and RPO commitments take precedence over internal targets, and business continuity does not depend on physical office sites.
PEOPLE & SUPPLIERS
Personnel with access to customer data are background-screened, contractually bound to confidentiality, and complete annual security and data protection training. Sub-processors are subject to due diligence, contractual security requirements and ongoing oversight; a current list is maintained within the Data Processing Agreement.
SHARED RESPONSIBILITY
Customers remain responsible for managing their own users, credentials, role assignments and end-user training within Thesis SM, and for assessing and notifying their own regulators or data subjects in the event of a breach, with Thesis providing the supporting evidence described above.
Contact
Security and privacy queries from customers and prospects could be addressed at: privacy@thesiscloud.com
The full Security Features document may be cited in due diligence and assurance exercises.