Compliance and assurance status
A clear distinction between existing evidence, independent attestations and the work needed to obtain them.
Version 1.1 · Updated 7 September 2026. Published by Glu IO Pty. Ltd., the owner and operator accountable for Helper Shifts. Committee-specific agreements take effect when signed.
Current status
No Helper Shifts SOC 2 report, ISO/IEC 27001 certificate, ST4S assessment/badge, Essential Eight maturity assessment or government approval is supplied or claimed. Provider certifications do not transfer to Helper Shifts, its staff processes or its application configuration.
Evidence currently available in this repository comprises application code, infrastructure definitions and automated tests. These support review of particular controls; they do not demonstrate sustained operational effectiveness or complete regulatory compliance.
ST4S assessment pathway
Confirm product eligibility and assessment sponsorship or process with ST4S, complete the readiness check, and supply the requested privacy, security and child-safety evidence. Resolve findings and keep the product and documentation in scope. Publish an outcome or badge only when authorised and keep it current under the programme’s rules.
See the ST4S badge programme. School-sector acceptance and any required mitigations remain separate decisions.
SOC 2
SOC 2 is an independent attestation report against applicable AICPA Trust Services Criteria, not an ISO-style certification. A Type I report addresses control design at a specified date; Type II also examines operating effectiveness over a period. Scope, report period, exceptions and complementary customer controls matter.
Preparation requires a defined system boundary, risk assessment, control owners, access reviews, change records, incident procedures, vendor oversight, backup tests and retained evidence. Engage an appropriately qualified independent CPA firm to agree scope and examination timing. A Type II report requires evidence across its examination period and cannot be generated by publishing these pages.
Reference: AICPA SOC 2 resources.
ISO/IEC 27001
ISO/IEC 27001:2022 specifies requirements for an information security management system. Preparation includes defined scope and leadership accountability, a risk assessment and treatment plan, a Statement of Applicability, documented policies, operational evidence, internal audit, management review and corrective action.
Certification requires assessment by an independent certification body and ongoing maintenance. Use an appropriately accredited body and verify the certificate’s entity, scope and validity. Merely mapping controls to the standard or using certified cloud infrastructure is not Helper Shifts certification.
Reference: ISO/IEC 27001.
Australian security frameworks
Use the ASD Essential Eight as a security baseline where applicable, and assess the relevant Information Security Manual or departmental framework when required by the customer. Establish a target and collect evidence before claiming a maturity level.
No Essential Eight maturity level, IRAP assessment or government security classification is claimed. The scope of cloud, application and staff-device controls needs to be explicit. School requirements may be stricter or differently scoped than these general frameworks.
Recommended implementation sequence
- Confirm the privacy contact with Glu IO Pty. Ltd., data inventory, live architecture and committee use case. Complete legal applicability and residency decisions.
- Establish measurable controls: privileged MFA, access reviews, patching, secure logs, tested backups, incident escalation, deletion and supplier management.
- Complete legal review and committee contract schedules. Gather evidence and seek ST4S assessment if eligible and relevant to committee use.
- Choose SOC 2 or ISO/IEC 27001 scope based on customer needs, assign control owners, operate the controls and retain evidence.
- Obtain independent assessment and publish only verifiable claims, with dates, scope and appropriate report-access controls.
Document history: version 1.1 — clarified independent committee use and contact responsibilities, 7 September 2026; version 1.0 — published documents, Australian data storage and Glu IO Pty. Ltd. operator identity, 7 September 2026; version 0.2 — clarified administrator contact-use restrictions, 7 September 2026; version 0.1 — initial publication, 6 September 2026. Print or save this page as PDF to retain this version. Committee agreements and applicable law take priority over general guidance.