About this dossier

Methodology & caveats

How this was gathered, what it can and can't tell you, and the lines we deliberately didn't cross.

What we did

Everything here comes from public, unauthenticated sources, queried on 24 July 2026. Nothing was logged into, scanned intrusively, or probed beyond loading pages the way any browser would. Specifically:

  • DNS recordsA, AAAA, MX, NS, TXT and _dmarc lookups, which reveal the host, mail provider, DNS operator and which SaaS platforms a domain has been verified against.
  • WHOIS / RDAP — registry data for each domain (registrar, creation and renewal dates, nameservers), via RDAP for .com/.org, Nominet for .uk, and Jisc's whois.ja.net for .ac.uk.
  • HTTP response headers — the Server, cache and framework headers that fingerprint the CMS, host and CDN (for example a ki-edge header reveals Kinsta; sg-cachepress reveals SiteGround).
  • The ICO public register — the Information Commissioner's Office data-protection register (ico.org.uk), the authoritative source for each controller's registration reference, registered address, expiry and its listed Data Protection Officer.
  • Published policies — each organisation's own privacy, cookie and data-protection notices, read as written, plus a look at what the live homepage actually loads (consent tool, analytics, trackers).

What it is — and isn't

A snapshot, not a live feed

Infrastructure changes. Hosts get migrated, DMARC gets tightened, trackers get added and removed. Every value here is a point-in-time reading from 24 July 2026. If you're relying on a specific detail, re-check it against the source before acting on it.

A fingerprint is evidence, not proof. A domain-verification record in DNS shows a service was connected at some point, not that it's actively in use. A tracking script present in a page's markup shows it loaded, not that it processed anyone's data unlawfully. Where we could confirm behaviour (a cookie actually set, a policy actually naming a processor) we said so; where we could only see a signal, we called it a signal.

The honesty standard

This site is part of the mathsschools.co.uk family, which sets out to be more honest than the schools' own marketing. That cuts both ways here. When a site's cookie banner doesn't match what it loads, we say so plainly — but we also note when a school gets it right (Cambridge and Exeter gate their analytics properly; U-Maths avoids third-party trackers entirely). The point isn't to name-and-shame; it's to describe accurately. Where research couldn't confirm something — a processor list locked inside a scanned PDF, a vendor we couldn't identify — the dossier says "not determined" rather than guessing.

What we left out on purpose

WHOIS for academic .ac.uk domains exposes a named individual as the administrative contact, often with a direct email and phone number. Those personal details are deliberately omitted — we record only the organisation-level registrant (the college, university or trust that owns the domain). This is a catalogue of institutional technology, not of the individuals who happen to administer a domain.

We also don't publish anything that would help someone attack these sites — no open-port scans, no software-version vulnerability mapping beyond what a normal page load reveals, no probing of admin interfaces.

Corrections

If you run one of these schools and something here is wrong or out of date, that's worth fixing — the underlying facts are observable, so a correction just means we re-checked. The main site's contact page is the route in.

Snapshot date
24 July 2026
Scope
12 specialist maths schools + the U-Maths network
Sources
Public DNS, WHOIS/RDAP, HTTP headers, published policies
Affiliation
None — independent
Browse the dossiers At a glance →