Student records, family contact details, attendance, grades, and tuition payments all live in one place. Here’s how we keep them safe — written plainly, no marketing fog.
Every service, every request, every user is verified. Role-based permissions for teachers, admins, parents, and students. No standing access.
Active alerting on reliability and security signals around the clock. We see issues the moment they appear — usually before anyone using the platform does.
Internal assessments, dependency & package validation, and a responsible-disclosure channel for researchers. Triage in days, fix on severity.
A signed Data Processing Agreement, transparent Privacy Policy, and Terms of Service. Your data is yours — exportable, deletable, never sold.
Our security program is operational, not aspirational. These practices are part of how the platform ships — every release, every dependency, every deploy.
We welcome responsible disclosure of potential security vulnerabilities. If you’ve found something, please reach out before going public — we’ll move fast.
We want researchers to feel safe reporting issues. If you act in good faith and within the expectations below, we won’t pursue legal action.
If something is wrong, you’ll see it on the status page before you have to ask. Every incident is logged with a public post-mortem once resolved.
We’d rather hear about it from you than from anywhere else. Security questions, DPA requests, audit support — we’re reachable.
Full vulnerability reporting policy, disclosure process, and safe-harbor terms.
How we handle, process, and protect personal data on behalf of schools.
What we collect, why we collect it, and what we never do with it.
The agreement that governs how schools and their users use the platform.