Security & data
Built for colleges to trust with learner data.
OutageLab is designed around what education providers need: minimal data, clear roles, tutor control and exportable evidence. This page summarises our approach for the pilot programme.
Student data is used only to provide the service
Learner names, attempts and scores are used to run the platform and give tutors progress and evidence. Nothing else. We don't sell data or use it for advertising.
No student data trains AI models by default
Student submissions are not used to train AI models by default. Optional AI features (mentor, review) send only the current attempt to the model to generate feedback, and can be turned off entirely.
Role-based access
Students see only their own work. Tutors see only their own classes. Roles are enforced on every page and API route.
Tutor-controlled assessment
Tutors control when scenarios run as timed assessments, the time limit, and when attempts lock, so assessment integrity stays with the educator.
Exportable evidence
Every attempt and learner profile can be exported as a clean, printable report, so your institution keeps its own records for moderation and audit.
Basic data deletion
On request at the end of a pilot or contract, we delete class, learner and attempt data. In the pilot edition, data is file-based and can be removed by clearing the data store.
Privacy policy
OutageLab privacy policy
Pilot edition · last updated 13 July 2026
1. Who we are
OutageLab provides network-troubleshooting training scenarios to education providers. For pilot deployments, OutageLab acts as a data processor on behalf of your institution (the data controller). Contact: pilots@outagelab.io.
2. What we collect
Account data (name, email address, role, class membership and a salted password hash) and learning activity (scenario attempts, submitted diagnoses, scores, hints used, time taken and terminal commands run during a lab). We do not collect payment details, device fingerprints, precise location or any special-category data, and we set only the cookies needed to keep you signed in.
3. How we use it
Solely to run the platform: signing you in, saving your attempts, showing tutors the progress and evidence for their own classes, and generating printable assessment reports. We do not sell personal data, share it with advertisers, or use student work to train AI models by default.
4. AI features
Optional AI features (mentor chat, AI review, scenario generation) send only the content of the current attempt to the AI provider to generate a response. These features can be disabled entirely, and their use is always visible to the learner.
5. Where data lives and how long we keep it
Pilot-edition data is stored in the application's data store for the duration of your pilot or contract. Attempts and reports are retained so tutors can moderate and export evidence. When a pilot or contract ends, class, learner and attempt data is deleted on request, normally within 30 days.
6. Sharing
Personal data is visible only to the learner it belongs to and the tutors of their classes. We share data with third parties only where needed to run the service (hosting infrastructure and, if enabled, the AI provider), never for marketing.
7. Your rights
Learners and staff can ask for a copy of their data, correction of inaccurate data, or deletion. Requests should go through your institution (the controller) or directly to pilots@outagelab.io, and we will respond within 30 days.
8. Changes to this policy
If this policy changes in a way that affects how learner data is handled, we will notify pilot institutions by email before the change takes effect.
On the roadmap
Not in the pilot edition yet, but planned for institutional rollouts:
- Cyber Essentials certification
- Single sign-on (SSO) for college identity providers
- LMS / VLE integration (Moodle, Canvas, Google Classroom)
- Regional data residency options
This is a plain-English summary for the research-preview pilot edition, not a contractual data-processing agreement. We'll provide a full DPA and security questionnaire responses as part of any department or enterprise agreement.