Legal & Governance

Security Policy

Security and data-protection practices for Asset Pilot EDU — written for parents, schools, and institutional partners.

Version:
1.0.0
Effective:
June 13, 2026

Last updated September 12, 2026

Security Overview

Asset Pilot EDU protects institutional and family information through role-based access, encrypted transport, hashed passwords, and careful handling of payments. This page summarizes practices suitable for parents and school partners. It is not a certification, penetration-test report, or legal opinion.

A printable Trust Center summary is available at /trust. Detailed internal controls for school IT and counsel are maintained separately for handoff.

Access Control

Role-based access governs administrator, staff (teacher), and parent visibility. Parent accounts are scoped on the server to linked students and related devices, repairs, payments, and evidence. New parent signups and student-link requests notify administrators; links remain pending until an administrator approves them, or until the parent’s email matches the student’s roster parent email (auto-approve). Privileged actions require authenticated sessions. Administrators may use audited “view as” impersonation for parent or teacher support; they cannot impersonate another administrator through that workflow.

Authentication

Sessions use HTTP-only cookies sealed with a server secret (iron-session). Production requires a configured SESSION_SECRET. Passwords are stored with bcrypt hashing. Login attempts are rate-limited to reduce brute-force risk.

Encryption and Transport

All production traffic is transmitted over TLS (HTTPS), with HSTS enabled. Database connections use encrypted channels to US-hosted PostgreSQL. Hosting providers apply managed encryption at rest for database storage. Asset Pilot does not claim separate application-level field encryption of every student field.

Card Payments

When online payments are enabled, parents pay through Stripe-hosted Checkout. Card number and CVV are not collected by Asset Pilot forms and are not stored in our database. We retain business payment records such as amount, status, and Stripe session identifiers.

Audit Logging

Device changes, repair actions, form signatures, wallet ledger notes, parent signup and link verification, password resets by administrators, and administrative impersonation are logged with timestamps to support institutional governance. Security alerts (pending parent links, suspicious linking activity) appear for administrators on the dashboard and Parent Links queue. Passwords and card numbers are not logged.

Monitoring and Incident Response

Platform health is monitored through hosting provider tooling. Operational status is published at /status. Security inquiries and incident reports may be directed to security@assetpilotedu.com. Schools should follow their own breach-notification policies with counsel.

Demo Environment Isolation

Demo experiences use sample data and do not write live student records. Demo accounts are blocked from live data mutations. The interactive demo is disabled in production unless explicitly enabled for sales or training.

Infrastructure Partners

Current subprocessors include Vercel (application hosting), Supabase (PostgreSQL), and Stripe when payments are enabled. Details also appear in the Privacy Policy.

Honest Limitations

No vendor can truthfully promise a system is unhackable. Our program focuses on reducing risk, detecting problems, and responding. Recommended hardening items (shared rate limits across servers, teacher API scoping, per-recipient messaging, and wallet top-up controls) continue on the product roadmap.