k12lms See a demo
Security and privacy

Things you can check, not things we claim

Every statement on this page describes behaviour you can verify in a demo. Where we have not built something, it says so.

Student privacy

The details that decide it

Most of what matters is not a policy. It is what the software does on an ordinary Tuesday.

Notifications carry no private details

A push notification never puts a student name, a grade, a health note or a balance on a lock screen. The alert carries an identifier and the app fetches the content over an authenticated connection once the phone is unlocked. A phone face up on a kitchen table says nothing about your child.

Uploads are scanned before anyone opens them

Every retained upload is checked and scanned by an antivirus engine before anyone can open it. Anything that fails is quarantined where it cannot be served or run. Enrollment documents stay locked to staff until the scan comes back clean.

Uploaded files have no public web address

Files are stored outside the website directory entirely and served only through an authenticated request that checks who is asking. There is no URL to guess and no folder to browse.

Guardians reach only their own children

A parent sees a child only through a recorded guardian link. Joining a parent conference is allowed for their own booked slot, their own child, within a short window either side of the appointment.

One access rule, everywhere

A single rule decides whether a member of staff may open a student record, and it is the same rule in every module. Teachers see their roster, the sections they co-teach, and students whose plans name them as case manager. Nurses, counselors and special education staff are school wide because their jobs are.

Every change is recorded

Administrative actions and field level edits are written to an audit trail with who, what and when. Enrollment approvals record the exact diff that was applied to the student record.

Virtual classrooms

The safest recording is the one that does not exist

Nothing is recorded

There is no recording feature. That means there is no classroom video to retain, redact, hand over in response to a records request, or lose.

Video never reaches our servers

Meetings are peer to peer, so classroom video travels device to device. We could not produce a copy if we were asked, because we never have one.

Access comes from the roster

There is no meeting link to distribute and nothing to forward. An administrator can see a meeting exists but must knock to enter, even on a locked room, and the teacher decides.

A camera goes off, never on

A host can switch a student camera off. No one can switch one on remotely.

Removal is reversible

A student removed from a meeting returns to the waiting room rather than being locked out, so a misclick during a lesson is not a crisis.

Drawing is attributed

Whiteboard strokes carry the account that made them, in a colour assigned rather than chosen. Clearing the board records the clear instead of destroying what was there.

Your data

Yours, in practice as well as in the contract

Never sold, never mined

Student data is not sold, not mined, and not used to target advertising. There is no advertising anywhere in the product.

Separated per school

Each school runs in its own database, with its own encryption key for confidential documents. Configuration secrets are encrypted at rest on the server and are not kept in source control.

Exports are a feature

Roster, enrollment, section, attendance and related datasets export as standard CSV whenever you want them. We do not charge for an export and we do not require notice.

Accounts are hardened

Passwords are never stored in a readable form and cannot be retrieved by us or shown back to anyone, including support. Repeated failed sign ins are throttled, and a failed attempt does not reveal whether the account exists. Sessions and API access can be revoked centrally, and API access is limited to what each integration needs.

Single sign on if you prefer

Google or Microsoft accounts, so staff and students keep the login they already have and your existing offboarding process still works.

Leaving is allowed

If you go, you go with your data. We would rather lose a district cleanly than hold one hostage.

Straight answers

What we have not done

A page about security that only lists strengths is a sales page. These are real gaps today.

No formal accessibility audit

We have not completed one and we will not imply otherwise. If a VPAT is a procurement requirement, tell us early and we will be straight with you about timing.

No outbound email or SMS

The platform cannot send email or text messages. Families are reached through the parent portal and app notifications. Where the product says it notified a parent, it means it recorded the contact.

No card payments yet

Fees and lunch are ledgers your office runs. Card payments through Stripe are in build, and when they arrive the money will go into the school's own Stripe account. The school stays the merchant of record and we never hold your funds.

State reporting is extracts

Clean, complete CSV datasets. They are not mapped to any single state's submission layout, so a person still does the final step.

Meetings cap at ten

Deliberate. Peer to peer video costs a school nothing to run. A media server carrying a class of twenty eight would add roughly four figures a month in bandwidth, and it would end up on your invoice.

The mobile app is English only

The core family pages on the web read in English and Spanish. The app does not yet.

This page describes what the product does, not how it is built. Districts whose procurement asks for implementation detail - hashing scheme, session handling, key management, retention, sub processors - should ask us for the security questionnaire response, which we send directly rather than publish. A public page is the wrong place for a map of the building.

If any of these is a blocker for your district, say so on the first call rather than the fifth. We would rather lose the deal early than waste your year.