Schoolletics™
Security approach

Access starts with role, organization, and purpose.

Schoolletics is built around authenticated, role-based experiences. A founding pilot limits its participants, programs, and data scope so the school can review the operating model before any expansion.

Technical foundations

Controls that are part of the current architecture.

These statements describe the implemented approach. They are not a claim of third-party certification or blanket regulatory compliance.

01

Authenticated boundaries

Dashboard reads and mutations are designed to travel through authenticated server boundaries rather than exposing privileged credentials to the browser.

02

Role-aware access

User roles and organization memberships are used to determine the workspace and data operations available to an authenticated account.

03

Fail-closed configuration

Production clients are designed to show an unavailable state when required live configuration is invalid rather than silently falling back to demo data.

Public website privacy

Anonymous conversion counts require consent.

The public marketing site asks before sending a small allowlisted conversion event to a first-party endpoint.

  • No analytics event is sent when a visitor declines or takes no action.
  • The event payload contains an approved event name rather than form content.
  • The public analytics implementation does not use browser cookies or local storage.
  • Demo form information is handled separately to respond to the request.
Pilot safeguards

Limit the first rollout to what can be owned and supported.

  • Name the participating organizations, programs, roles, and users.
  • Agree on the minimum data needed for the workflow.
  • Verify access behavior for each participating role.
  • Document support and escalation contacts.
  • Review retention, deletion, provider, and policy requirements before expansion.
No certification claim

Schoolletics does not represent this page as a SOC 2, ISO 27001, FERPA, COPPA, HIPAA, or other compliance certification. School-specific legal, privacy, procurement, and data-processing requirements must be reviewed before a live-data pilot.

Bring your security questions early.

We will separate what is implemented today from what your school would require before a live-data rollout.

Schedule a review