- A score appears and no one can explain why
- AI suggestions and approved school guidance are blurred
- Trust documents list features the tool cannot perform
Advisory, bounded, transparent, auditable — and human-owned.
Children's data, work and next steps deserve a system you can inspect. Outleap keeps AI assistance bounded to school workflows, gives staff full visibility of the feedback students receive, scopes access by role and school, and never trains on pupil data. Where roadmap features are coming in September 2026, their guardrails are designed in, not bolted on.
From a black box you have to trust to a system you can inspect.
Most AI tools ask a school to take the model's word for it. Outleap is built the other way round. Every AI step is advisory, bounded and visible to staff, and the trust pack describes only what is processed today.
- AI is advisory; it suggests and explains, it does not decide
- Access is scoped to role; no training on pupil data
- Trust pack scoped to what we actually process today
Live today, and built to extend.
Some guardrails govern the product as it runs now. Others are designed into the Opportunity Radar coming September 2026. We keep the two clearly separated, so a trust review never confuses a live control with a roadmap intention.
Advisory, bounded feedback (live)
AI feedback is advisory and bounded to the student's own draft: a headline summary, priority actions and section strengths and improvements. It never scores or grades a child, and staff see every student's feedback in full through normal product views.
Role-scoped access, no training on pupil data (live)
Access is scoped by role and by school, and tenancy is strictly separated. We do not train models on pupil data; statements, evidence, CV/application records where enabled, and feedback are processed to run the service for your school, not to improve a model used elsewhere.
Supervised radar guardrails (Sep 2026)
The Opportunity Radar is being built so every suggestion carries a source, a reason it is shown and a verified date, with no auto-submit and no hidden sensitive-data profiling. These ship with the radar, not before.
Designed for an under-18 cohort.
This is a service for children, and the Children's Code is the standard a cautious Data Protection Lead looks for first. We name our alignment in plain school-facing language, not only in the legal documents.
High privacy by default
Settings start private. A student controls their own progression profile, and nothing about a child is exposed more widely than the school's process requires.
Best interests of the child
Design choices are made for the student's benefit. There are no nudges that weaken a child's privacy, and no dark patterns pushing a young person to share more.
Data minimisation
We collect what the progression process needs and no more. Metrics measure quality movement such as a route recorded or timely support before a deadline, never vanity counts of clicks.
Aligned to how the DfE expects AI to be used in schools.
The DfE's guidance on generative AI in education sets clear expectations. We map to them on the page, so your IT lead and DPO can check the posture before they read a single policy document.
Transparency
AI involvement is visible, not hidden. Feedback is clearly labelled as AI-assisted support, not approved school text. The radar is being built so every suggestion shows its source and a human-readable reason.
No training on pupil data, with fact-checking
Pupil data is not used to train models, and AI output is treated as advisory — never a verdict on a child. Staff see the feedback every student receives through normal product views, and the school remains responsible for any safeguarding escalation.
DPO and IT involvement
The trust pack is written for your DPO and IT lead to interrogate. We expect involvement from data protection and IT, and we scope our documents to what we actually process so that involvement is straightforward.
Scoped to what we actually process.
The trust pack describes today's processing: the Evidence Bank, the UCAS three-question statement workflow, advisory AI feedback with full staff visibility, school-owned safeguarding escalation, and CV/application workspaces where enabled. Automated safeguarding alert delivery and routing are not active in the launch product. Opportunity Radar and References are not listed as current use because they are coming September 2026. Lawful basis sits with you as controller, documented in your own DPIA. We give you accurate inputs, not a binding misstatement to inherit.
Trust documents that can support school review.
School leaders, safeguarding teams, and procurement reviewers should be able to see the core documents before a rollout conversation gets stuck in document chasing.
Controller-processor terms for school procurement and legal review.
DPIA starterA practical starting point for school Data Protection Impact Assessment review.
Subprocessor listCurrent providers, purposes, data categories, and processing locations.
Data-flow descriptionThe account, workflow, AI-processing, storage, and delivery path.
Retention policyRetention categories, review cadence, and deletion posture for school data.
AI safety policyAdvisory, bounded AI use, transparency, staff visibility, and school-facing safeguards.
Read it through the lens of a 17-year-old's data.
Bring your DPO, IT lead and DSL. We will walk how AI feedback works and what staff can see, school-owned safeguarding escalation, CV/application scope where enabled, role-scoped access and the no-training position, then hand over the trust pack so your DPIA describes only what we actually process.
Book a trust review