The page to forward to IT and procurement. Here's how we handle data, access, and integration, plainly.
TLS/HTTPS in transit and AES-256 at rest. Hosted on AWS in the United States; the database runs in a private network and is never publicly reachable.
PostgreSQL row-level security forces every query to a single district. The app connects through a least-privilege role, so one tenant can't read another's data even if app code had a bug, not just a UI filter.
Granular roles so people see only what their role allows. Sessions re-check role and status on every request, so deactivating a departed employee takes effect immediately. SSO available for district rollouts.
No student PII is required to run the platform; we process staff data. Where we touch education records we act as a school official with legitimate educational interest, under your direction.
We'll sign your data privacy agreement (including SDPC / NDPA and state forms). Our subprocessor list (AWS, Amazon SES, Stripe) is published, with notice of material changes.
AI-assisted features run on a commercial model provider under terms that don't use your inputs to train their models. We don't sell data or use it for advertising. Details in the full overview.
One document that answers the questions a district IT or security team actually asks, written to be accurate, not aspirational. Share it directly with your reviewers.
Read the full security overviewWe don't replace your SIS or HRIS. Staff and roster data flow in from the systems you already run; we add the coaching, listening, and retention layer they were never built for.