A student’s name, a guardian’s email and a coach’s honest remark are sensitive together. Nothing here is sold, mined or used to train anything.
Encrypted in transit and at rest
TLS 1.3 on every connection, AES-256 on stored records and attachments.
Least privilege by default
A coach sees their own batches. A director sees their branch. Nobody browses everything.
Guardian consent recorded
Every parent email address carries the date and source of its consent to be contacted.
Audit log on every report
Who wrote it, who edited it, who it went to, when it was opened. Exportable.
Deletion that means deletion
Remove a student and their records leave backups within 30 days. Confirmation in writing.
No advertising, no training
Student data is never sold, never used for ads, never fed to a model.
| Framework | Status | Detail |
|---|---|---|
| GDPR | Compliant | DPA on request; EU data residency on Institution |
| FERPA | Aligned | School official designation supported |
| COPPA | Aligned | No direct-to-child accounts or messaging |
| SOC 2 Type II | In audit | Observation window closes this year |
| Penetration test | Annual | Third-party; summary shared under NDA |
Free for 30 days. Add your roster in an afternoon; the first reports go out the same evening.