01 / TRUST

Trust.

One row per commitment, in plain language. These are practices we follow, written the way we’d want them explained to us.

ACCESSWe can access the systems named in your agreement, through accounts you can see and revoke. We never touch student work, email content, or anything outside scope.
DATA LOCATIONYour data lives in systems your school holds administrator access to — Google Workspace, your SIS, your backup target. Per-tier specifics are written into the agreement.
ACCESS CONTROLNamed individuals only, scoped per system, MFA enforced, reviewed quarterly. Every grant is visible to you.
BACKUP & RESTOREBackups run on a schedule and restores are tested on a schedule. A backup that has never been restored is treated as no backup.
FILTERING & CIPAContent filtering configured and tested per device, aligned with CIPA expectations for schools receiving E-Rate funding.
FERPA & COPPAWe operate as a school official with a legitimate educational interest under FERPA where applicable, and we don’t collect data from students directly. We describe practices — we don’t claim certifications we don’t hold.
PRIVACY AGREEMENTSWe work through your data privacy agreement — including NDPA-format agreements — before anything is signed.
OFFBOARDINGYou keep every credential, every document, every backup. Offboarding is contractual and takes an afternoon, not a negotiation.
INCIDENTSIf something goes wrong, you hear it from us first — with a stated notification window, what happened, what was affected, and what we’re doing.

We describe practices rather than claiming certifications. Regulatory wording is reviewed before it becomes part of any agreement.