Skip to main content
ST4S · Australia and New Zealand education

Get your product in front of schools with a stronger ST4S assessment.

Education departments across Australia and New Zealand use ST4S to judge whether school technology is safe enough to adopt. Summit helps edtech vendors prepare with gap analysis, penetration testing evidence and a clear plan to close findings.

Human-led VAPT · NDA first · report in 48h

5
assessment areas: security, privacy, interoperability, safety and artificial intelligence
2
countries: Australia and New Zealand
Free
to take part, according to the New Zealand Ministry of Education supplier page
Low / Medium
risk ratings that make a product eligible to apply for the ST4S badge
Board and leadership view

Why ST4S matters to your board

The work is technical. The consequences of getting ST4S wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Revenue and market access

If departments and schools check ST4S status before buying, a missing or poor result can close the door on whole states or on New Zealand.

Children's data and liability

Student data carries high expectations. A breach involving children is a serious legal and reputational event.

Reputation with schools

Schools talk to each other. A clear rating and a badge build trust faster than any sales deck.

Deadlines and ownership

Assessment queues and school buying cycles are fixed. Someone senior should own the timeline and the evidence.

Fit

Who usually needs ST4S

Edtech and learning platforms

Schools and departments check ST4S status before approving a platform for classroom use.

Student information and communication tools

Products holding student records or messaging children face the closest scrutiny on privacy and safety.

Overseas vendors entering the market

If you sell into Australian or New Zealand schools from elsewhere, expect to be asked for ST4S status.

Assessment and content services

Anything that handles student data or accounts, even indirectly, may be asked for the same evidence.

Scope of work

What Summit delivers for ST4S

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your product measured against the current Vendor Guide, with a prioritised fix list.

Penetration testing

Manual testing of web, mobile and API layers, including tenancy and student-data exposure.

Control validation

We check that the controls you describe actually work as written.

Evidence pack

Policies, test reports and diagrams organised for the questionnaires.

Remediation support and retest

Support while your team fixes findings, then a retest to confirm closure.

Board-ready report

An executive summary of risk, readiness and decisions, with technical detail behind it.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A realistic ST4S preparation roadmap

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Scope the product

    Week 1

    Decide which product, environments and data flows will be assessed, and download the current Vendor Guide.

  2. 2

    Readiness Check, gap analysis and fixes

    Weeks 1 to 12

    Compare your product with the minimum requirements, close gaps in security, privacy and safety, and write the evidence assessors will ask for.

  3. 3

    Test security

    Month 2 to 3

    Commission manual penetration testing and fix the findings, so you can show vulnerabilities found and closed.

  4. 4

    Request assessment and respond

    Varies

    Submit questionnaires and evidence if selected, then review draft findings with the ST4S team.

  5. 5

    Apply for the badge

    After the final report

    If rated low or medium risk, apply for the badge and plan annual reviews.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Which product and data flows are in scope?

    Be precise about modules, integrations and where student data lives.

  • Who owns the submission?

    One accountable owner keeps questionnaires, evidence and follow-up moving.

  • What does our privacy policy really say?

    Assessors compare it with how the product behaves.

  • How do we use AI with student data?

    Have a clear, honest position ready before you are asked.

  • What is the commercial deadline?

    Work back from the school term or tender date you are targeting.

The detail

What ST4S actually is

Safer Technologies 4 Schools (ST4S) is a national initiative that assesses the security, privacy and safety of digital products used in schools. It is run by Education Services Australia (ESA), a ministerial not-for-profit company, with the support of Australian state and territory education departments, the Catholic and independent sectors and the New Zealand Ministry of Education.

Schools and departments use ST4S results to decide which products are safe to adopt. Vendors typically begin with the ST4S Readiness Check, an optional online survey based on the Vendor Guide, then ask to be prioritised for a full assessment. If selected, you submit detailed questionnaires with supporting documents, review draft findings and receive a final report. Products rated low or medium risk can apply for an ST4S badge.

The assessment looks at security, privacy, interoperability, safety and artificial intelligence. Exact requirements, evidence expectations and timings change, so always work from the current Vendor Guide on the ST4S website.

Key terms in plain English

Readiness Check
An optional online survey based on the ST4S Vendor Guide that shows how close a product is to the minimum requirements.
Full assessment
The formal review where the vendor submits questionnaires and evidence and ST4S assessors examine them.
Risk rating
The overall result of the assessment, which decides whether a product can apply for the badge.
ST4S badge
A mark showing a product has met the nationally agreed minimum standard.
Requirements

What the assessment looks at

ST4S works from a nationally consistent control framework. These are the areas vendors most often need to prepare for. Check the current Vendor Guide for the exact questions.

1

Security controls

Assessors look at how you protect accounts, data and infrastructure. Expect questions on encryption, access control, secure development, vulnerability management and incident response.

What it looks like in practice

  • Encryption of student data in transit and at rest
  • Multi-factor authentication for staff and admin access
  • Independent penetration test results with fixes tracked
  • A tested incident response and notification process
2

Privacy and data handling

Products that handle student and staff personal information must show clear, lawful data practices that align with the relevant Australian or New Zealand privacy requirements.

What it looks like in practice

  • A plain-English privacy policy that matches real data use
  • Defined retention and deletion for student data
  • Records of where data is stored and who can access it
  • Controls on advertising and secondary use of student data
3

Interoperability

Schools expect products to exchange data cleanly with other school systems. Assessors look at data formats, APIs and integration approaches.

What it looks like in practice

  • Documented APIs and data formats
  • Secure authentication for integrations
  • Support for standard roster and identity approaches
4

Safety

For products that reach students directly, safety covers content moderation, age-appropriate design and how users can report problems.

What it looks like in practice

  • Reporting and moderation workflows
  • Age-appropriate defaults for younger users
  • Controls on contact between users
5

Artificial intelligence

Where a product uses AI, assessors ask about governance, safeguards and how student data is used.

What it looks like in practice

  • A clear statement of where AI is used
  • Controls on whether student data trains models
  • Human oversight for decisions that affect students
Where testing fits

How penetration testing supports ST4S

ST4S security assessment expects you to show how you find and fix vulnerabilities. Check the current Vendor Guide for exact penetration testing requirements. A manual test with a retest gives assessors a clear record.

Security

Application testing

Testing of web, mobile and API layers where students and staff log in and handle data.

Security

Access control and tenancy

Checks that one school or user cannot see another's records.

Privacy

Data exposure

Verification that student data is not leaked through APIs, logs or storage.

Evidence

Report and retest

A dated report, remediation log and retest confirmation to attach to your submission.

Avoid these

Common ST4S mistakes, and how to avoid them

!

Waiting for the assessment to find gaps

Use the Readiness Check first. Fixing gaps before submission shortens the process.

!

Treating it as only a security questionnaire

Privacy, safety and interoperability carry equal weight. A strong security answer does not offset weak privacy practices.

!

Submitting scanner output as test evidence

Assessors and schools prefer to see a human tester explore the product, with fixes confirmed by retest.

!

Letting evidence go stale

Policies, test reports and architecture diagrams should reflect the product as it is today.

FAQ

ST4S questions, answered

What is ST4S?

ST4S, Safer Technologies 4 Schools, is a national initiative that assesses the security, privacy and safety of digital products used in schools in Australia and New Zealand.

Who runs ST4S?

Education Services Australia (ESA), a ministerial not-for-profit company, runs it with support from Australian state and territory education departments, the Catholic and independent sectors and the New Zealand Ministry of Education.

How do vendors apply?

Most vendors start with the optional Readiness Check, then ask to be prioritised for a full assessment. If selected, you submit questionnaires and evidence, review draft findings and receive a final report.

What does the assessment cover?

Security, privacy, interoperability, safety and artificial intelligence. Read the current Vendor Guide on the ST4S website for the detailed requirements.

Is ST4S mandatory?

It is not a law. In practice many schools and education departments check ST4S status before adopting a product, so it often decides whether a sale goes ahead.

Is there a fee?

The New Zealand Ministry of Education states participation is free. Confirm current terms on the ST4S website, and budget for your own preparation and testing.

Does ST4S require a penetration test?

Check the current Vendor Guide for the exact requirement. Independent penetration test results are widely used as evidence of security practice and are worth having ready.

Ready to get ST4S sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →