Sign in

Security & data

Built for colleges to trust with learner data.

OutageLab is designed around what education providers need: minimal data, clear roles, tutor control and exportable evidence. This page summarises our approach for the pilot programme.

Student data is used only to provide the service

Learner names, attempts and scores are used to run the platform and give tutors progress and evidence. Nothing else. We don't sell data or use it for advertising.

No student data trains AI models by default

Student submissions are not used to train AI models by default. Optional AI features (mentor, review) send only the current attempt to the model to generate feedback, and can be turned off entirely.

Role-based access

Students see only their own work. Tutors see only their own classes. Roles are enforced on every page and API route.

Tutor-controlled assessment

Tutors control when scenarios run as timed assessments, the time limit, and when attempts lock, so assessment integrity stays with the educator.

Exportable evidence

Every attempt and learner profile can be exported as a clean, printable report, so your institution keeps its own records for moderation and audit.

Basic data deletion

On request at the end of a pilot or contract, we delete class, learner and attempt data. In the pilot edition, data is file-based and can be removed by clearing the data store.

Privacy policy

OutageLab privacy policy

Pilot edition · last updated 13 July 2026

1. Who we are

OutageLab provides network-troubleshooting training scenarios to education providers. For pilot deployments, OutageLab acts as a data processor on behalf of your institution (the data controller). Contact: pilots@outagelab.io.

2. What we collect

Account data (name, email address, role, class membership and a salted password hash) and learning activity (scenario attempts, submitted diagnoses, scores, hints used, time taken and terminal commands run during a lab). We do not collect payment details, device fingerprints, precise location or any special-category data, and we set only the cookies needed to keep you signed in.

3. How we use it

Solely to run the platform: signing you in, saving your attempts, showing tutors the progress and evidence for their own classes, and generating printable assessment reports. We do not sell personal data, share it with advertisers, or use student work to train AI models by default.

4. AI features

Optional AI features (mentor chat, AI review, scenario generation) send only the content of the current attempt to the AI provider to generate a response. These features can be disabled entirely, and their use is always visible to the learner.

5. Where data lives and how long we keep it

Pilot-edition data is stored in the application's data store for the duration of your pilot or contract. Attempts and reports are retained so tutors can moderate and export evidence. When a pilot or contract ends, class, learner and attempt data is deleted on request, normally within 30 days.

6. Sharing

Personal data is visible only to the learner it belongs to and the tutors of their classes. We share data with third parties only where needed to run the service (hosting infrastructure and, if enabled, the AI provider), never for marketing.

7. Your rights

Learners and staff can ask for a copy of their data, correction of inaccurate data, or deletion. Requests should go through your institution (the controller) or directly to pilots@outagelab.io, and we will respond within 30 days.

8. Changes to this policy

If this policy changes in a way that affects how learner data is handled, we will notify pilot institutions by email before the change takes effect.

On the roadmap

Not in the pilot edition yet, but planned for institutional rollouts:

  • Cyber Essentials certification
  • Single sign-on (SSO) for college identity providers
  • LMS / VLE integration (Moodle, Canvas, Google Classroom)
  • Regional data residency options

This is a plain-English summary for the research-preview pilot edition, not a contractual data-processing agreement. We'll provide a full DPA and security questionnaire responses as part of any department or enterprise agreement.