Acorn CCMS

Trust & data protection

Sensitive data, treated like it.

Acorn holds children, families, staff and medical records — the most sensitive information a centre keeps. Protecting it isn't a feature we added. It's the foundation the whole platform is built on.

How we protect your centre

Security built into the foundations.

Every part of Acorn is designed around one principle: your centre's data is yours, isolated from everyone else's, and accessible only to the people you choose.

Isolated by centre

Organisation and centre boundaries are part of Acorn's data model from day one — not a setting bolted on later. Your records are never mingled with another centre's.

Access you control

Role-aware access and permission checks run across staff, records and centre operations — so educators, administrators and directors each see what they should.

Encrypted in transit

Connections to Acorn are encrypted end to end. Data moving between your team and the platform is protected over modern TLS.

Audit trail

A record of what changed and when means compliance reviews start from facts, not memory — and accountability is built in, not retro-fitted.

Backed up & recoverable

Managed hosting means regular backups, monitoring and recovery procedures are handled for you — without a server for your centre to run.

Privacy by design

Acorn is built for the Australian context with privacy obligations in mind — collecting what a centre needs to operate, and nothing it doesn't.

Multi-tenant, done right

Your data, walled off by design.

Acorn was multi-tenant from the very first commit. Organisation and centre isolation is enforced in the data-access layer — every query, every record, every request is scoped to your centre. There's no "shared table" your information can leak through.

Centre-scoped access checks

Permission boundaries are evaluated on the server, on every request — not trusted from the browser.

Least-privilege by default

People and integrations get the minimum access needed for their role, and no more.

AI within your boundaries

The Acorn AI assistant works inside the same tenant boundaries and permission checks as the rest of the app.

Run for you

Hosting and operations, handled.

Acorn is fully hosted, so the operational security work that usually lands on a centre — patching, monitoring, backups, upgrades — is ours to carry.

Have a specific compliance requirement? If your service, council or provider needs detail on our security posture, data handling or sub-processors, we're happy to walk through it.

Talk to us
Managed backups

Regular backups with tested recovery, so a bad day never means lost records.

Monitoring & upgrades

The platform is monitored and kept current — security updates roll out without a project on your end.

Hardened authentication

Sessions and sign-in are built with hardening in mind to keep accounts protected.

Your data stays yours

Export your records and leave whenever you choose — Acorn is built to be data-portable, not a lock-in.

Questions, answered

Security questions we hear most.

Is our centre's data isolated from other centres?
Yes. Acorn has been multi-tenant since day one. Organisation and centre boundaries are enforced in the data-access layer, so every request is scoped to your centre and your records are never combined with another service's.
Who can see our children's and families' information?
Only the people you authorise. Role-aware permissions mean educators, administrators and directors each see the records appropriate to their role, with access checked on the server for every request.
Do you use our data to train AI models?
The Acorn AI assistant works on your centre's data to answer your questions and draft documentation, within the same permission boundaries as the rest of the app. For specifics on AI data handling for your service, get in touch and we'll walk you through it.
What happens to our data if we stop using Acorn?
Your data stays yours. Acorn is designed to be data-portable, so you can export your records and leave on your terms — there's no hostage-taking of your centre's history.
How are backups and recovery handled?
Because Acorn is fully hosted, regular backups, monitoring and recovery procedures are managed for you — there are no servers or backup jobs for your centre to run.

Run your centre on a platform that protects it.

Start a free trial, or talk to us about the security details that matter to your service.