Security & privacy

These are children’srecords. We treat them so.

A student’s name, a guardian’s email and a coach’s honest remark are sensitive together. Nothing here is sold, mined or used to train anything.


Encrypted in transit and at rest

TLS 1.3 on every connection, AES-256 on stored records and attachments.

Least privilege by default

A coach sees their own batches. A director sees their branch. Nobody browses everything.

Guardian consent recorded

Every parent email address carries the date and source of its consent to be contacted.

Audit log on every report

Who wrote it, who edited it, who it went to, when it was opened. Exportable.

Deletion that means deletion

Remove a student and their records leave backups within 30 days. Confirmation in writing.

No advertising, no training

Student data is never sold, never used for ads, never fed to a model.


Compliance

Where we stand

FrameworkStatusDetail
GDPRCompliantDPA on request; EU data residency on Institution
FERPAAlignedSchool official designation supported
COPPAAlignedNo direct-to-child accounts or messaging
SOC 2 Type IIIn auditObservation window closes this year
Penetration testAnnualThird-party; summary shared under NDA

Your next session isa report waiting to happen.

Create your console

Free for 30 days. Add your roster in an afternoon; the first reports go out the same evening.