VISecurity & data

Student data is sacred
sacred.

NoteA product about children is also a product about consent, ownership, and discretion. The defaults here are not negotiable.

IFive promises
/Promise · 0101

The data leaves with the student.

When a child finishes school — or earlier, if they leave us — a complete export of their signal map is delivered to them in 24 hours. JSON, portable, theirs. We retain nothing after a 30-day grace period. This is non-negotiable and pre-dates any commercial conversation we have with a school.

/Promise · 0202

What we measure, we publish.

We measure understanding. We do not measure behaviour, attendance, emotional state, social dynamics, or anything outside the classroom and the homework session. Everything we measure is documented on /method, including the failure modes of each signal.

/Promise · 0303

No cross-school modelling without consent.

We do not train models on one school's data and use them at another without the originating school's explicit, written, revocable consent. Per-school priors stay per-school. The exception is our open-source aggregate research, which is conducted only on anonymised, school-approved datasets and published in full.

/Promise · 0404

Parents see what the school sees.

The signal map is the same map for every stakeholder. We do not show the school one number and the parent a different one. If a parent asks for a deeper view than the school's report shows, we direct the parent to the school — never around it.

/Promise · 0505

The child sees themselves first.

Where age and consent allow, the child sees their map before anyone else does. This is the most important design decision in the product. The child is not a subject of assessment; they are the assessor's first audience.

The data belongs to the student. We are custodians, not owners.
IIThe technical floor
For your IT review

Things a careful IT lead will want to know before signing.

We publish this here rather than putting it behind a sales conversation. If anything below is a deal-breaker for the school's IT review, we'd rather know on day one.

  • /01 · HostingAWS Mumbai region · India-resident data only
  • /02 · EncryptionTLS 1.3 in transit · AES-256 at rest
  • /03 · Access controlPer-school RBAC · audit log on every read
  • /04 · BackupEncrypted daily snapshot · 30-day retention
  • /05 · AuthenticationSchool-managed SSO where supported · 2FA mandatory for staff
  • /06 · Sub-processorsListed publicly · 30-day notice on any change

☞ Full data-processing addendum available on request, signed and versioned.

Begin a careful pilot ↗