Trust Centre

Your story. Your record. Protected by design.

GradWIN is the place where everything you've already achieved becomes one trusted professional story. We treat that story — and the people writing it — with the same care a university or your future employer would expect.

This page is maintained by GradWIN to answer common questions from students, parents, universities, recruiters, and investors. It describes the controls we have in place today and the roadmap we are building toward. It is not an independent certification.

Privacy

Your information belongs to you.

We only collect what's needed to build your professional record: who you are, where you study, the goals you've set, the badges you've earned, and the moments you've chosen to celebrate. You can read, edit, export, or delete your information from inside the app.

  • University email is verified once, then stored as a locked snapshot — your login email can always change.
  • You can request account deletion from your Profile at any time.
  • We follow the Australian Privacy Principles (APPs) and are building toward GDPR-aligned controls.
  • We never sell your data. Ever.

Security

Defence in depth, every layer.

Every student record is protected by row-level security at the database. Admin actions are written to an immutable audit log. Suspicious patterns — failed logins, scraping, prompt-injection attempts — surface as alerts to our security team in real time.

  • TLS in transit, encryption at rest.
  • OWASP Top 10 + OWASP API Top 10 used as our baseline standard.
  • Regular Security Red Team exercises before significant releases.
  • Founder-signed incident response: 72-hour notification commitment to affected users.

Responsible AI

AI that helps, never harms.

Our Coach uses AI to help students get unstuck inside GradWIN. It is intentionally narrow. It cannot reveal its prompts, expose code, accept jailbreak attempts, or do anything outside of helping you use the product.

  • All AI conversations are logged for moderation and abuse detection.
  • Suspicious behaviour is escalated to our Security Centre automatically.
  • AI-assisted badge reviews are advisory only — humans verify before any record becomes official.
  • We will publish a Data Protection Impact Assessment for AI features pre-launch.

Availability

A record you can rely on.

Your record matters to your future. We run on resilient cloud infrastructure with automated backups, daily monitoring of platform health, and kill-switches that let us contain an incident without losing data.

A public status page is on the roadmap for our Series A milestone.

Compliance Roadmap

Built toward enterprise standards.

We are designing GradWIN with the discipline expected of an enterprise platform — because universities, recruiters and investors deserve nothing less. Internally we track our maturity against nine frameworks, including the Australian Privacy Principles, OWASP Top 10, OWASP API Top 10, Five Eyes Secure-by-Design, ASVS Level 1, ISO 27001 readiness, SOC 2 readiness, GDPR, and FERPA.

We do not claim certifications we do not hold. We do commit, transparently, to the path.

Security Testing

We invite responsible disclosure.

Found something that doesn't feel right? Email hello@gradwin.app and we'll respond within 2 business days. We commit to acknowledging legitimate findings publicly (with your permission) once they are resolved.

Documents

Policies & resources.

Have a question we haven't answered? We'd genuinely like to hear it.

hello@gradwin.app