Trust & Security

Trust & Security

Built for Institutional Accountability

Asset Pilot EDU supports K–12 technology operations with role-based access, secure sessions, and clear limits on what family accounts can see. We focus on reducing risk and protecting integrity — not impossible guarantees.

Security & Data Protection

Asset Pilot EDU protects school and family information with role boundaries, secure sessions, and Stripe-hosted payments when cards are used. Practices below match how the live product works — not marketing guarantees.

  • Role-Based Access

    Administrators, teachers, and parents receive different visibility. Parents are limited to students linked to their account after school verification (or email match to the roster).

  • Signed-In Sessions

    Portal sessions use HTTP-only cookies. Passwords are stored as irreversible hashes, not plain text.

  • Encrypted Connections

    Production traffic uses HTTPS with HSTS. Database hosting uses provider-managed encryption at rest.

  • Card Payments via Stripe

    When online pay is enabled, card numbers are entered on Stripe’s pages — not stored in Asset Pilot.

  • Operational Audit Trails

    Form signatures, impersonation, and key device actions are logged to support school accountability.

  • Continuous Hardening

    We reduce risk, monitor, and improve controls. No system can honestly promise it is unhackable.

Operational Reliability

  • Infrastructure Visibility

    Operational systems are designed to support administrative continuity.

  • Recovery Readiness

    Platform architecture supports restoration planning and continuity processes.

  • Continuous Improvement

    Security and operational processes evolve alongside platform maturity.

Governance Principles

  • Least Privilege Access

    Accounts receive only the visibility required for their role — admin, teacher, or parent.

  • Operational Accountability

    Signatures, impersonation, and key device actions support review and institutional oversight.

  • Single-School Pilot Boundaries

    The current deployment serves one school’s data. Multi-school tenant isolation is a future product step, not a present marketing claim.

  • Institutional Transparency

    Trust and legal pages explain hosting partners, payments, and parent scoping in plain English.

Privacy Principles

  • Data minimization

    We process information needed to run devices, repairs, forms, and family portals.

  • School ownership

    The deploying school remains the custodian of student education records.

  • Parent scoping

    Parent accounts see linked children and related devices, repairs, and payments — not the full student roster.

  • Transparency

    Public policies describe subprocessors (Vercel, Supabase, Stripe when enabled) in plain language.

  • No student advertising

    We do not sell personal information or use student data for unrelated advertising.

These pages describe platform practices for parents and schools. They are not legal advice; schools should consult counsel for FERPA, COPPA, and institutional policy questions.

Operational Trust

Asset Pilot EDU is designed to support institutional technology operations through structured workflows, operational accountability, and transparent governance practices.