Built for institutions that take data seriously
Encryption, consent integrity, audit trails and regulatory awareness — engineered in from the start, not bolted on.
Security controls
Encryption at rest
Signed, single-use consent tokens
Rate limiting
Immutable audit trail
Data minimisation
Access control
Compliance
Designed for the regulatory reality of education.
FERPA
Student education records are treated with the confidentiality FERPA requires. Institutions stay in control of their data and who can access it.
COPPA
Minors only participate with verifiable parental consent. The age-of-majority threshold is configurable per institution, and parent emails are required for minors on the roster.
Data Processing Agreement
A DPA template is available for your records and can be tailored to your institution before you go live.
SOC 2 roadmap
We operate with SOC 2 principles in mind — least privilege, encryption, audit logging, incident response — and are on a roadmap to formal SOC 2 readiness.
Incident response & transparency
- Every consent state change is logged with actor, timestamp and metadata — we can reconstruct exactly what happened and when.
- Security incidents are triaged by the engineering team and affected institutions are notified with a clear summary and remediation plan.
- Backups of the database are taken daily, and restore is tested on a schedule.
- Keys and secrets are held in environment-level secret management, not in the repository.
Want the details for your security review?
We'll walk your IT and legal teams through architecture, controls and the DPA.
Request a demo