MICKAI®SectorsMulti-Academy Trusts (Primary and Secondary)
Team
Sector · Safeguarding intelligence that never leaves the trust.

Multi-Academy Trusts (Primary and Secondary)

Multi-academy trusts hold some of the most sensitive records in the public sector: child data, safeguarding logs, attendance flags and pastoral notes spanning thousands of pupils across dozens of schools. Trusts want to spot vulnerable students earlier by joining these signals together, but UK GDPR Article 8 protections for children's data and statutory safeguarding duties make it unacceptable to send that material to a third-party cloud for processing. Mickai installs the full AI capability on hardware the trust owns, under keys the trust holds, so safeguarding analytics run air-gapped inside the trust's own estate. This removes the third-party cloud-exposure vector for child data, and the trust keeps its existing safeguarding and data-protection obligations intact.

The problem and our solution
The buyer

Multi-academy trusts and their central safeguarding, data-protection and IT leadership.

The problem

GDPR Article 8 child data and safeguarding records cannot sit on a third-party cloud, yet the signals that flag vulnerable pupils are scattered across schools and systems.

Our sovereign solution

Air-gapped safeguarding analytics installed on hardware the trust owns, under keys the trust holds, joining pupil signals across every academy inside the trust's own estate.

The value

Vulnerable students are flagged earlier, the third-party cloud-exposure vector for child data is removed, and what happens in the server room stays in the server room.

The sovereign advantages

These architectural choices support control over the workflows in your deployment. Their benefits depend on configuration, integrations and operating practices. Review external connections, physical security, access and compliance responsibilities together.

Control the processing boundary

Scope inference, extraction, retrieval and storage on infrastructure you control. Document and test any external connector, support channel or transfer before describing a workflow as zero-egress.

Plan for disconnected work

Workflows with local models, data and supporting services can continue offline. Live external email, calendars and other services need an approved connection or controlled import, with clear unavailable and pending states.

Make data location inspectable

Map prompts, documents, indexes, logs and backups to their processing and storage locations. Local hosting supports control of location; access, retention and any transfers still need review.

Use approved company knowledge

Prepare and classify source records, preserve permissions and evaluate answers against the originals. Retrieval and model training are separate choices; agree data use and licences for each.

Budget for the whole service

Compare hardware and licences alongside integration, power, administration, support, updates, evaluation and recovery. Measure cost at the required workload and quality before claiming savings.

Verify access and authority

Define who holds keys, who can administer the system and which actions need approval. Test denied requests, revoked access and audit records. Physical security, insider risk and incident response remain operational responsibilities.

Control change and exit

Agree version selection, signed update procedures, rollback, data export and licence rights. Reassess requirements as software and obligations change; owning hardware does not remove maintenance or compliance work.

Requirements to assess

Review the requirements relevant to your organisation, jurisdiction and intended use with your responsible teams. Cloud services can be appropriate subject to applicable safeguards; on-premise deployment alone does not establish compliance or remove supplier responsibilities.

UK GDPR Article 8 (conditions applicable to a child's consent and the protection of children's personal data)
Keeping Children Safe in Education (KCSIE) statutory safeguarding guidance
Working Together to Safeguard Children and the trust's statutory safeguarding duties
Department for Education data protection and data-handling requirements for schools and trusts
Data Protection Act 2018 and the Information Commissioner's Office (ICO)
Organisations of this profile

The kind of organisation this serves, named illustratively from public information to characterise the market. These are target profiles, not customers: Mickai has no relationship, engagement, trial, or endorsement with any of them.

United LearningArk SchoolsHarris Federation
The lead studios

The enterprise studios that lead in this sector, drawn from the eighteen that sit on the one sovereign substrate. Scope their local processing, operator-held keys and Open Audit Record coverage for the proposed deployment. Confirm availability and any external integrations before relying on a workflow.

Department studio

Compliance and Regulator Mode

Maps every safeguarding workflow to UK GDPR Article 8, KCSIE and DfE data rules, and produces the audit-ready records a trust needs to evidence lawful processing of child data on its own estate.

Department studio

Executive BI

Gives the trust board and central team a cross-school view of safeguarding, attendance and wellbeing signals so vulnerable students surface earlier, while pupil data stays inside the trust.

Department studio

CRM

Holds the unified pupil and family record that ties pastoral, attendance and safeguarding contacts together inside the trust, replacing scattered third-party tools that would otherwise widen child-data exposure.

Department studio

Training and LMS

Runs staff safeguarding and KCSIE training and tracks completion across every academy, keeping designated-safeguarding-lead readiness current trust-wide.

Department studio

HR

Manages staff vetting status, safer-recruitment checks and central HR records across all schools in the trust on hardware the trust controls.

See all eighteen on the sovereign services catalogue.

The opportunity

Multi-academy trusts are consolidating central functions across growing numbers of schools while facing tightening expectations on how children's data is handled, which creates strong demand for safeguarding and pupil-data analytics that can run without exporting child records to external processors. A sovereign, on-premises capability lets trusts modernise safeguarding insight while removing the cross-border-transfer and third-party-processing friction that cloud tools introduce.

The outcome

Measure value, cost and risk on hardware you control.

Trusts gain earlier identification of vulnerable students from joined-up safeguarding, attendance and pastoral signals while removing the third-party cloud-exposure vector for child data; physical and insider controls remain the trust's own. Running independent of the internet and external vendors also displaces recurring per-pupil SaaS and cloud-processing costs and narrows the data-protection-impact-assessment surface that external processors would otherwise widen.

Lawful B2B engagement

Map the sovereign stack to your multi-academy trusts (primary and secondary) estate.

Briefings are for organisations weighing a sovereign, on-premises deployment. Tell us about your estate and we will walk the pack, the regulatory crosswalk, and the deployment that fits your estate.

Other sectors
Retail with customer-data depth
Retail
Law firms and legal-ops
Legal
Banking, insurance, and financial services
Finance
NHS Trusts and private healthcare
Healthcare
Defence and government
Public Sector
Generational discretion and an uncompromised deal edge, on hardware you own.
VCs and Family Offices
Multi-generational wealth, processed entirely inside your own walls.
Private Banking and Wealth
The ledger never leaves the firm.
Accounting, Tax and Audit
Price the risk without surrendering the risk profile.
Insurance and Actuarial
Sovereign discovery infrastructure for assets too valuable to leave the building.
Pharma, Biotech and Pre-patent IP
Quality auditing of device and calibration data that never leaves the building.
Medical Devices
Bunker-grade AI for work that can never touch the public cloud.
Defence, Aerospace and Dual-Use
Off-grid intelligence for the systems a nation cannot afford to lose.
Critical Infrastructure, Maritime and Energy
Your process is your moat. Keep it inside the factory walls.
Heavy Industry, Manufacturing and Semiconductors
Network intelligence that never leaves the core
Telecommunications
Sovereign research intelligence that keeps the IP, and the dual-use risk, on campus.
Academic and University Research
Sift the whole talent pool without the raw records ever leaving your building.
Executive Search and HR
Athlete telemetry and tactics that never leave the training ground.
Elite Sport and Performance
The client black book that never leaves the room.
Luxury, Private Aviation and VIP Concierge
Clienteling and collections held in the house, not the cloud.
Luxury Fashion
Tag every frame on premises, so no pixel ever leaves the studio.
Commercial Photography and Media Houses
Sovereign deal intelligence for the agencies that hold the industry's secrets.
Talent and Literary Agencies
Your catalogue, indexed and searchable, with no master ever leaving the building.
Music Studios and Labels
Source protection that never leaves the newsroom.
Press and Investigative Journalism
The IP lifecycle stays under lock and key, from script to final pixel.
Film, TV and VFX
Where the question paper never leaves the vault until test day.
Examination and Testing Boards
Special-needs records that never leave the setting
SEN and Alternative Provision
Ship native AI for schools without inheriting the data-processing-agreement fight.
EdTech and LMS Vendors