Security

What protects your family's information, what we cannot promise, and what we have not earned yet. This page is written the way we would want a vendor to write it for us: specific things a reviewer can check, and no adjectives.

The controls that matter most

Nothing happens without your yes

Every consequential thing the agent does (emailing your school, submitting a form, placing a call) waits for your explicit approval. That is enforced in code, not by asking the AI nicely: the action runner refuses to execute a step that is not approved, and a stray message like "ok thanks" does not count as approval.

Filling a form and submitting it are two separate steps

The agent fills a form and stops. It shows you what it filled, and only after you say yes does a second, separate step submit it. There is no code path that submits before you approve.

We only say "submitted" when the school's own page confirms it

A browser run reporting that it finished is not evidence that anything was submitted. So we require the confirmation the site itself shows and the reference number it gives back. If we cannot see a confirmation, we tell you we could not confirm it, even if the run says it finished. A failed submission is never reported as a success.

Your phone proves it is you

Before the agent does anything, you confirm a six digit code sent to your own number. Until then there is no account and no work.

How your information is protected

WhatHow
Connections and credentials we hold (such as a connected mailbox token) Encrypted with AES-256-GCM, and the encrypted value is tied to the family it belongs to, so a record copied to another account cannot be opened
Data in transit TLS between your phone, our servers, and the services we use
Family records and messages at rest Stored in our database, encrypted at rest by the host, with row level security scoped to the family in the schema, and reachable only through our server. They are not individually encrypted field by field, and we say so rather than implying otherwise
Application logs Names, email addresses and phone numbers are masked before anything is written, by field and by pattern. If an email address appears in a tool call, the log line holds a placeholder, not the address
Browser sessions Session recording is switched off. A recording of your child's school portal would be the largest thing we could accidentally keep, and we do not need the video, only the page
Webhooks we accept Both inbound endpoints reject anything unsigned or stale. They fail closed: if the signing secret is missing, the request is refused rather than trusted
Secrets Not in the source code. A check runs on every change to catch a key shaped string before it can be committed

Who processes your information

We are a small team, so we use established providers rather than building everything. Here is who sees what.

ProviderWhat it sees
AnthropicYour messages and family details, to write replies and do research
OpenAIPage content from the sites the agent reads
SkyvernForm details and page content, and a saved school portal sign in while you stay connected
BrowserbaseThe browsing session (recording is off)
TavilySearch queries about schools and districts
ResendEmails we send to a school when your Gmail is not connected
GoogleGmail and Calendar, only if you connect them
RetellPhone calls, if you ask us to call
Supabase, Railway, VercelWhere data is stored, hosted and logged

We do not sell your information and we do not use it for advertising. A service that reads web pages and writes emails cannot promise that nothing is ever shared: your messages do reach our model provider, and that provider reads them to write the reply. What we can say is that we know which providers are involved, that list is above, and nothing goes to your school or anyone else until you approve the exact message or form.

Where your information is processed

Our own systems and the model inference for your messages run in the United States. Some of our providers use support, security and identity vendors in Canada, South Africa and the United Kingdom. Those vendors can see limited account and support data. They do not receive your child's profile. We do not claim that your information never leaves the United States, because that would not be true.

What we can delete, and what we cannot

Text reset and we delete your family's data: the profile, your children, the cases, the messages, the emails we triaged, and the connected mailbox token. We disconnect the saved school portal sign in first, because that is a live key to your account. We keep one record saying a deletion happened, with the date and the counts, and none of the content.

These we cannot delete, and we will not pretend otherwise:

What an AI agent cannot promise

An agent that reads web pages and email can be tricked by text inside them. That risk is real, it is not fully solvable, and any vendor telling you otherwise is wrong.

What we do about it:

What we have not earned yet

This is the part most vendors leave out. All of it is true as of the date below.

Certification or controlStatus
SOC 2 report We do not have one. We will not describe a report we do not hold, and we will not use the word compliant for something we have not been examined on. If you need one for procurement, we will tell you plainly that it does not exist yet
Signed data processing agreements In progress, not complete for every provider listed above. We will not claim they are all in place until they are
Independent penetration test Not yet done
HIPAA or FERPA compliance We do not claim either. FERPA binds schools, not vendors like us, and the school official designation is the district's to make. We act on your own access to your child's information, with your permission
End to end encryption We do not claim it. To write a reply, our systems have to read your message, which means we hold it in readable form
Accessibility The public pages are plain HTML: every word of the content is there before any script runs, so the site works without JavaScript. The pages are built to WCAG 2.2 AA (contrast, focus visibility, landmarks, labels, touch targets, reduced motion). We have not completed a formal third-party audit
Compliance certifications (HITRUST, ISO) None held

What we do have

Report a security issue

Report it through our contact form. We will acknowledge your report, tell you what we think, and fix what is real. We will not threaten or pursue someone who reports a problem in good faith. The full policy, including what is in scope and what we ask of you, is in our vulnerability disclosure policy.

Last reviewed: September 2026. If any statement here stops being true, we change the page. A security page that lags behind the system is worse than no security page.