Arbor School Management Information System for Multi-Academy Trusts
Arbor MIS is a cloud-based management suite for multi-academy trust schools and central MAT teams. It combines multi-school student, staff and operations data. With built-in automation, AI-assisted tools and integrations across HR, finance and timetabling, Arbor is transforming work in schools with insight and time-saving features.
Features
- Full cloud-based School MIS supporting teaching, attendance, behaviour and assessments
- Trust-wide real-time dashboards with drill-down to individual schools
- Parent, student and staff portals for communication and payments
- Automate school and trust processes using automatic workflows
- Built-in AI tools to support communications, reporting and data analysis
- Attendance, behaviour and assessment tracking with automated follow-up
- Secure role-based access for schools and central teams
- Integration with HR, finance, timetabling and partner systems
- Trust-wide pushdowns for settings, policies and processes
- Timetabling and curriculum integration supporting day-to-day school operations
Benefits
- A single source of truth across schools and central teams
- Reduces manual processes and inconsistent ways of working
- Improves visibility of performance, attendance and staffing across the trust
- Enables trust-wide consistency while supporting school autonomy
- Saves time through automation of repetitive administrative processes
- Supports better, faster decision-making with real-time data
- Reduces reporting burden on schools
- Improves collaboration between schools and central teams
- Supports trusts to scale and onboard new schools efficiently
- Enables secure, flexible working for distributed trust teams
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 2 2 6 5 9 4 3 6 8 8 6 4 6
Contact
ARBOR EDUCATION PARTNERS GROUP LTD
Phillippa De'Ath
Email: bids@arbor-education.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- We recommend users work in the Chrome or Microsoft Edge browsers, with a minimum internet bandwidth of 2MB, but there are no known hardware constraints.
- System requirements
-
- Recommended browser: Chrome or Microsoft Edge
- Recommended internet bandwidth: 2MB
User support
- Email or online ticketing support
- Yes
- Support response times
-
We aim to respond to users as quickly as possible when queries come in. Our email and phone lines are staffed 8-5, Monday-Friday by a team of experienced analysts.
Our Service Level Agreement (the maximum time we would ever expect to take) for responding to urgent queries is 1 working hour, rising to 24 for low priority queries. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- We have a dedicated engineering team that works specifically on front-end user experience and managing our accessibility of Arbor for our users, including the support areas of the site. They have tested a number of assistive technologies with the site over the past year of development such as keyboard controls and colourblind browser settings.
- Onsite support
- Yes, at extra cost
- Support levels
-
Schools will be supported through their migration, training and needs at all key points through their first term. Our team will run kick-off calls, provide instructions, and help you run your data checks, in addition to the usual email and phone support. After your MIS is fully embedded in the school, the project team will hand you over to your Customer Success Manager who will look after you for the rest of your time with Arbor.
This onboarding service and further training options are priced in our pricing document. Customer Success Management is included in the licence for the rest of your contract. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We have Prince2 certified project managers who work with Multi-Academy Trusts. Your schools will be scheduled to meet a specialist via web conference to plan their data migration, training and implementation. For secondary schools we will also run a practice migration to check their data is behaving as expected prior to the final migration. Data migration instructions will be sent to the school depending on their current MIS, usually on a Friday afternoon following final registration. Pre-Launch webinar training will be provided.
Thereafter, for the first term we will check in with you regularly to understand the project status, implementation and answer any questions. Further Post-Launch training is usually provided once users have got going, for more detailed system areas such as custom report building, progress tracking or Trust-wide administration for MATs.
You will have access to our online learning as soon as you sign, and when any user logs in for the first time the system intelligently gives them a tour of the site and the key features they'll need. All help documentation can be accessed online via the application, and is also searchable without logging in to Arbor. Documentation includes videos, product gifs and written instructions. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Searchable Help Centre website
- Video introductions & guides
- Live webinars with a library of prior webinars
- In-app walkthroughs and information
- End-of-contract data extraction
-
Data processed in Arbor will always be owned by the school. Data can be removed from Arbor in the following ways:
• Through an Arbor Standard Migration Export, which exports all essential data from your Arbor backup in .csv format.
• As reports using the Custom Report Writer which can then be exported in Excel, CSV, PDF, Word or XML.
• As Common Transfer Files (CTFs) containing all basic student data.
• As downloaded files that match their upload format e.g. pictures added to profiles, PDFs added to medical records. - End-of-contract process
-
The Arbor standard license agreement covers support, hosting, upgrades, maintenance, and software license for the selected tier of MIS.
Should the institution wish to fully terminate their service after the Initial Licence Period for that service, including the deletion of all historic data processed by the service, free or otherwise, it must give 30 days’ notice in writing to Arbor’s registered address that complete deletion of data is required. There will then be a 60 day countdown period during which time the institution can extract their data, before the MIS is switched off.
Access to an Arbor site will cease on the contract end date. After the contract end date we are no longer the appointed Data Processor, and in line with the General Data Protection Regulation (EU) 2016/679, the data will be permanently deleted after 30 days.
If the institution have not extracted their data after the contract end date, they can request access to export their data for a further 48 hours. This is possible up to 30 days after the end date, after which time data is permanently deleted. There is an administration fee of £500 (+VAT) for this extension. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The Arbor Parent App allows parents to access their Parent Portal on Android or iOS, so they can make payments, receive push notifications from the school, arrange clubs, trips and parents evenings, update their children's data, and more. The Arbor Student App likewise allows them to access their Student Portal online, with their timetable, assignments, and daily info.
The MIS user interface is also reactive meaning it can be accessed through the browser of a phone or tablet as you would do on a computer. This allows e.g. teachers to view class information and seating plans to take the register. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Our user interface is clear and accessible, with colour coding and all displays carefully considered to ensure a consistent user experience across the site. Graphs, callouts, and slideovers break up the screen to introduce significant information in engaging ways, according to a standard set of design guidelines.
By creating a consistent and attractive user experience, we can guarantee the meaning of each component is clear and memorable. Experienced users can guess how to find and use data on any page, even if they have not been to that particular area of the site before. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Arbor is used by over 650 special and alternative provision schools across the country, and by students, parents, and staff experiencing a range of special needs and disabilities. We regularly collect feedback from all users, including schools and users with additional needs. Accordingly, our interface is customisable through browser-based accessibility controls. We recommend Google Chrome for the best range of accessibility controls and plugins, such as their high contrast, colourblind, and greyscale modes.
- API
- Yes
- What users can and can't do using the API
-
Arbor's full REST and GraphQL APIs allow you to integrate your app and reach our entire network of schools with your product or service. Integrating with Arbor is completely free, and we provide full developer documentation and Software Developer Kits to help you get started. Once we’ve vetted an app, they can become an Arbor approved partner. We can migrate app data from a previous MIS to sync with Arbor, maintaining historic data records.
The Developer Portal is the first place to find answers to technical queries relating to Arbor’s open, REST and GraphQL APIs. We also partner with Wonde, Groupcall and Zinet to maintain a simpler interface to the API to allow app developers to read and write to the Arbor database.
There are no operating system or database constraints, but Arbor reserves the right to rescind access by third parties if the API is misused. Access to the API is granted by school administrators only; no third party will be able to access a school's Arbor-stored data unless we have been given the explicit, written consent of the data controller in that school. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Arbor is a highly customisable system which will be set up to match school priorities. During implementation, we will work with you on each of our customisable features to make sure their languages and processes work best for you and your goals.
Workflows: customisable for behaviour, progress tracking and intervention management
Curriculum: any curriculum can be imported and tracked against
Assessment frameworks: can be set up in limitless ways
Custom Report builder: any data fields can be pulled into custom reports that can be read within the application or exported to Excel, Word, Google Docs, XML or Excel/GDoc live feed.
Users can customise based on role: usually school administrators will set up and push out workflows or assessment features to their own schools.
Scaling
- Independence of resources
-
1. Architecture is housed in a private firewalled network, within which we operate a strict single-tenanted database model.
2. Dynamically-sized worker pool
Amazon EC2 instance optimised for high memory and data storage.
3. Massively Parallel Analytics Engine
The dynamic worker pool is combined with a job server to allow large, complex querying of datasets, with results returned in real-time.
4. Dynamically-sized web instance pool
Amazon instance optimised for high CPU power analytics.
5.Elastic load balancer
Uses Amazon’s Elastic Load Balancer to reroute traffic across multiple instances.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Feature usage:
- Monitored by Arbor support analysts to evaluate training needs.
- Monitored by Product Managers to identify feature adoption issues and to improve usability.
Guardian usage:
- Adoption metrics are available to Arbor school administrators to identify engaged parents and to automate follow ups to those who have not used the system.
Staff usage:
- The 'Users and Security' feature shows MIS login history in the past thirty days, the last login date of each user, and the access permissions users have.
- Each staff page has a 'System Engagement' section that shows their individual service usage. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can print, export to CSV/Excel or PDF.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- CTF
- Word
- ATF
- XML
- Read from the Arbor API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CTF
- ATF
- Excel
- XML
- Write back to the Arbor API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We will use our reasonable endeavours to maximise uptime, and ensure that the System is available least 99.8% of the time averaged over each year, with no two months in a row falling below 99.8%. This excludes (i) any of our or our subcontractors' maintenance downtime, (ii) a failure between the Institution's computer(s) and the internet; (iii) factors outside of our reasonable control; (iv) the Institution's action or inaction, or any action or inaction of the Users or the Institution's other suppliers.
Service credits are available if this SLA is not met for our Advanced Support customers. - Approach to resilience
-
Our datacentre, hosted by Amazon Web Services in London, is resilient and certified ISO 27001, ISO 27017 and ISO 27018 compliant.
Architecture is housed in a private firewalled network to reduce external access and increase security. Instances are recycled daily to reduce the risk of data being compromised; servers are patched continuously to reduce security vulnerabilities.
Further information is available on request. - Outage reporting
- By email alerts to Arbor users, or our online status page.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
System Access: Access is granted to various business systems based on defined Access Control Policy. We conduct regular Access Control reviews. We maintain a test/demo system that minimises the need for support access to production systems.
Server Access: Access to servers by our engineers follows a zero-trust practice requiring written justification and an independent verification of the access request. Once approved, temporary access credentials are only valid for the requested duration and automatically revoked once the session ends. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We adhere to a robust Information Security Management System (ISMS) and are certified to ISO 27001:2013 and Cyber Essentials. Our infrastructure provider, Amazon Web Services, is also ISO 27001 certified. Security is integral to our design, employing bank grade 256-bit SSL for data in transit and AES-256 for data at rest. Physical access is restricted with 24/7 security and CCTV, while digital access utilizes two-factor authentication and strict need-to-know permissions. We continuously monitor for vulnerabilities, patch servers nightly, and conduct annual penetration testing. For data breaches, our policy is to report to customers within 24 hours. All staff are DBS checked and receive continuous data protection training. Our supply chain partners are contractually bound to uphold these security standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All systems are configured using SaltStack. No changes are ever made to live server configurations (we operate with immutable servers). Salt allows us to define the end state of the system declaratively in salt state files which are version controlled. This means that any changes to the configuration of servers leave an audit trail. It also means that all configuration can be tested in our staging environment and repeated deterministically. All changes are assessed by the Head of Technical Security Operations before being approved.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Assessing: We run a monthly Security Committee to assess potential threats to our services. In addition, there is a quarterly Management Information Security Review to ensure effectiveness of the information security management system. A dedicated DevOps team subscribes to relevant security briefings and assesses the risk on a daily basis. We commission external penetration tests at least once per year.
Patching: All systems are configured to download and install security updates nightly, and the installed updates are checked via a centralized log. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Monitoring: All changes to any data records are kept in an Audit Log. All errors are logged to a centralized error reporting system and investigated by relevant engineering teams. All user activity, page requests, system and server logs are aggregated in a centralized log. All services are continually monitored into a centralized system.
Identification: Automatic alerts are sent to DevOps/engineers whenever breaches/errors are identified.
Response: Incidents are assessed and classified. Serious incidents are reported to the CTO and our Incident Response Policy is followed to completion (48 hours). Minor incidents are resolved by individual teams (14 days). - Incident management type
- Supplier-defined controls
- Incident management approach
-
The security incident response plan aligns with the SANS Identification step and is about making use of a robust detection and reporting capability. Early visibility of incidents facilitates quick decision making and rapid action. Potential security incidents can be detected and reported from a number of different sources, such as:
Arbor employees.
Arbor customers.
Arbor business partners.
Other external sources such as Law Enforcement Agencies.
System logs.
For non-system reporting our support line can be contacted to report a perceived security event or security weakness.
Security related incidents are centrally recorded using an Incident Log. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We run limited time offers of free usage for schools with existing MIS licences who need to move before their current licence expires. This covers the Arbor Core package only.
- Link to free trial
- https://login.arbor.sc/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Tuesday 24 March 2020
- What the ISO/IEC 27001 doesn’t cover
- Our ISO 27001:2013 certification is comprehensive, covering the entirety of our information security management system across all offices and systems. We do not exclude any internal business systems or geographic locations from this scope, ensuring that every aspect of our operations meets this international benchmark for data security. While our certification specifically validates our internal management processes and the security of platforms, it is important to note that it does not extend to the independent internal infrastructure of the schools we serve or third-party hardware managed locally by clients.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 10 January 2023
- What the ISO 9001 doesn’t cover
- Our ISO 9001:2015 certification is an internationally recognised gold standard that ensures our quality management systems are measurably effective and subject to independent annual audits. We added this certification specifically to provide assurance for our customer services, ensuring that our internal processes for supporting schools and trusts meet rigorous quality benchmarks.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eaa86dd2-b784-4b53-bee1-76f80b5f6903
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-