Security Trust Center — Live Status: All Systems Operational

Security is not an add-on module.
It is our core foundation.

After PowerSchool's breach exposed 62 million student records, school districts deserve full transparency. We publish our architecture, isolation specs, and pen testing results.

SOC 2 Type II
FERPA
COPPA
CIPA
WCAG 2.1 AA
Ed-Fi ODS v3
The Catalyst Event

Why PowerSchool's breach forced a fundamental shift in K-12 software.

In December 2024, PowerSchool suffered the largest student data breach in American history. The vulnerability was architectural: a shared database schema without strict multi-tenant engine isolation and optional MFA authentication for staff.

POWERSCHOOL ARCHITECTURAL ROOT CAUSES

Flaws Exposed
Shared database tables without engine-level RLS policies
Optional MFA enabled credential harvesting attacks
Application-level authorization checks that failed under bypass payload

BREACH TIMELINE & REGULATORY IMPACT

National K-12 Security Audit

Dec 2024 — Present
PowerSchool Data Breach DisclosedDec 2024

62 million student records exposed across North America due to shared database architecture.

State Investigations InitiatedJan 2025

Multiple Departments of Education and Privacy Commissioners open formal audits.

Attacker Guilty Plea ConfirmedMay 2025

Federal court documents reveal root cause: optional MFA and unsegregated database schemas.

Districts Mandate Zero-Trust SISPresent

Districts nationally require published zero-trust architecture before renewing SIS contracts.

● Federal & State Architecture Compliance Mandates Active
Architecture Deep-Dive

Six non-negotiable security layers

Click any security pillar to inspect our technical specification.

Zero-Trust Architecture

No Implicit Trust

PostgreSQL Row-Level Security (RLS)

Engine-Level Isolation

Database transactions execute set_config('app.tenant_id', tenantId) bound by AsyncLocalStorage. RLS policies force the DB engine itself to reject cross-tenant queries.

Enforced at PostgreSQL engine level — zero reliance on app code
AsyncLocalStorage binds tenant identity to every request lifecycle
Cross-tenant data leakage is mathematically impossible
Solves the root cause of PowerSchool's architecture flaw

Encryption at Rest & In Transit

AES-256 + TLS 1.3

Mandatory WebAuthn MFA

Phishing-Resistant

83,000-Line Granular RBAC Engine

Deep Scoping

Immutable 7-Year Audit Logs

Tamper-Proof

Live Posture Verification

Zero-Trust Security Controls

Enforced 24/7
Mandatory MFA
WebAuthn Passkeys
Tenant Isolation
PostgreSQL RLS
Encryption at Rest
AES-256 GCM
Encryption in Transit
TLS 1.3 Minimum
Audit Log Retention
7 Years Immutable

Infrastructure & Isolation Specifications

Cloud Infrastructure

Cloudflare Workers

Global Edge · 300+ Cities

Edge Runtime

V8 Isolates

No Shared Container Tenancy

Database

Postgres + Tenant RLS

Row-Level Isolation Per District

Disaster Recovery

Blue / Green Failover

R2 Snapshots · Automated Rollback

Availability SLA

99.9% / 99.99%

Standard / District+ Tier

Incident SLA

< 1 Hour Notice

Mandatory Transparency

Build your district on a secure foundation.
Zero compromise on student privacy.