IT one-sheet, Network requirements | The Business School
For Heads For Teachers Curriculum Licensing Resources FAQ Join the waitlist Department case
For your IT team

IT one-sheet: network requirements.

Everything needed to run the simulation on a school network, on one page.

Two ways to get this to IT
thebusiness.school/it/

Copy that link and paste it into an email to IT, or download the ready-made PDF below to attach directly.

Download the PDF version ↓

How to send this to your IT team

Forward this sheet to your network team with the message below.

Hi, I would like to run The Business School, a live classroom business simulation, with my class. Please could you whitelist play.thebusiness.school and thebusiness.school so students can join. All traffic is standard HTTPS on port 443, browser only, nothing to install. Full details are in the attached sheet.

1 · Domains to whitelist

Allow these domains through the school's web filter and firewall. All traffic is HTTPS.

thebusiness.schoolWebsite & teacher resources
play.thebusiness.schoolThe simulation itself, students & teachers
*.thebusiness.schoolSimplest rule if wildcards are supported
fonts.googleapis.com · fonts.gstatic.comWeb fonts, loaded by the simulation's stylesheet
2 · Connections & bandwidth

HTTPS, port 443 only

Standard secure web traffic. No custom ports, no VPN, nothing to install.

WebSocket connections

Live gameplay uses secure WebSockets (wss://) to the same domains. Most filters pass these; if the game stalls behind a proxy, allow WebSocket traffic to play.thebusiness.school.

Light bandwidth

Text and small data updates, no video streaming. A full class of 32 runs comfortably on ordinary school Wi-Fi.

EU cloud hosting

Sessions are managed server-side in the EU. No peer-to-peer connections between student devices.

3 · Devices

Any device with a modern browser: Chromebooks, Windows/Mac laptops, iPads and phones. No installation, no browser extensions, no admin rights. Recent versions of Chrome, Edge, Safari and Firefox are all supported.

4 · Accounts & data

A student joins with a 6-digit PIN and a nickname they choose. We process that nickname, the decisions they make in the game and the answers they write. In the connected version of Founder’s Hour a student is identified by their first name and last initial instead of a nickname. Only the teacher has a login. The answers a student writes are sent to a language model so that it can mark them and the teacher gets a report, and they are not used to train the model. Student data and game states are deleted after 30 days. The school is the data controller and TBS Education Ltd Oy is the data processor. TBS Education Ltd Oy is ICO registered, registration ZC133810, verifiable at ico.org.uk.

Full details on the data protection and trust & safety pages.

5 · Sub-processors

Three sub-processors are involved in running a session. Your students’ devices only ever connect to the domains listed in section 1; the rest is server to server.

NetlifyHosting and functions, US and global network
NeonDatabase, EU, Frankfurt
OpenAIMarks the answers students write

Schools are told at least 30 days before a sub-processor is added or replaced, and may object.

Something blocked on your network?

Tell us what your filter reports and we'll help you get running, usually it's just the WebSocket rule.

Contact us