Security
What protects your family's information, what we cannot promise, and what we have not earned yet. This page is written the way we would want a vendor to write it for us: specific things a reviewer can check, and no adjectives.
The controls that matter most
Nothing happens without your yes
Every consequential thing the agent does (emailing your school, submitting a form, placing a call) waits for your explicit approval. That is enforced in code, not by asking the AI nicely: the action runner refuses to execute a step that is not approved, and a stray message like "ok thanks" does not count as approval.
Filling a form and submitting it are two separate steps
The agent fills a form and stops. It shows you what it filled, and only after you say yes does a second, separate step submit it. There is no code path that submits before you approve.
We only say "submitted" when the school's own page confirms it
A browser run reporting that it finished is not evidence that anything was submitted. So we require the confirmation the site itself shows and the reference number it gives back. If we cannot see a confirmation, we tell you we could not confirm it, even if the run says it finished. A failed submission is never reported as a success.
Your phone proves it is you
Before the agent does anything, you confirm a six digit code sent to your own number. Until then there is no account and no work.
How your information is protected
| What | How |
|---|---|
| Connections and credentials we hold (such as a connected mailbox token) | Encrypted with AES-256-GCM, and the encrypted value is tied to the family it belongs to, so a record copied to another account cannot be opened |
| Data in transit | TLS between your phone, our servers, and the services we use |
| Family records and messages at rest | Stored in our database, encrypted at rest by the host, with row level security scoped to the family in the schema, and reachable only through our server. They are not individually encrypted field by field, and we say so rather than implying otherwise |
| Application logs | Names, email addresses and phone numbers are masked before anything is written, by field and by pattern. If an email address appears in a tool call, the log line holds a placeholder, not the address |
| Browser sessions | Session recording is switched off. A recording of your child's school portal would be the largest thing we could accidentally keep, and we do not need the video, only the page |
| Webhooks we accept | Both inbound endpoints reject anything unsigned or stale. They fail closed: if the signing secret is missing, the request is refused rather than trusted |
| Secrets | Not in the source code. A check runs on every change to catch a key shaped string before it can be committed |
Who processes your information
We are a small team, so we use established providers rather than building everything. Here is who sees what.
| Provider | What it sees |
|---|---|
| Anthropic | Your messages and family details, to write replies and do research |
| OpenAI | Page content from the sites the agent reads |
| Skyvern | Form details and page content, and a saved school portal sign in while you stay connected |
| Browserbase | The browsing session (recording is off) |
| Tavily | Search queries about schools and districts |
| Resend | Emails we send to a school when your Gmail is not connected |
| Gmail and Calendar, only if you connect them | |
| Retell | Phone calls, if you ask us to call |
| Supabase, Railway, Vercel | Where data is stored, hosted and logged |
We do not sell your information and we do not use it for advertising. A service that reads web pages and writes emails cannot promise that nothing is ever shared: your messages do reach our model provider, and that provider reads them to write the reply. What we can say is that we know which providers are involved, that list is above, and nothing goes to your school or anyone else until you approve the exact message or form.
Where your information is processed
Our own systems and the model inference for your messages run in the United States. Some of our providers use support, security and identity vendors in Canada, South Africa and the United Kingdom. Those vendors can see limited account and support data. They do not receive your child's profile. We do not claim that your information never leaves the United States, because that would not be true.
What we can delete, and what we cannot
Text reset and we delete your family's data: the profile, your children, the
cases, the messages, the emails we triaged, and the connected mailbox token. We disconnect the
saved school portal sign in first, because that is a live key to your account. We keep one
record saying a deletion happened, with the date and the counts, and none of the content.
These we cannot delete, and we will not pretend otherwise:
- Encrypted backups, which clear on a rolling cycle.
- Copies our AI providers keep for a period under their own safety and anti-abuse rules. That is typically 30 days, and in rare safety cases it can be much longer.
- Emails already sent to a school. Those cannot be recalled.
What an AI agent cannot promise
An agent that reads web pages and email can be tricked by text inside them. That risk is real, it is not fully solvable, and any vendor telling you otherwise is wrong.
What we do about it:
- Nothing consequential runs without your explicit yes, so a tricked agent still has to ask you.
- Filling and submitting are separate, so a page cannot cause a submission on its own.
- We treat page and email content as information to read, never as instructions to follow.
- Addresses we reply to come from the message you received, not from instructions inside a page.
- We are adding further code level limits on which sites the browser may visit and which actions may run at all, so that the boundary is enforced by the program rather than by asking the model to behave.
What we have not earned yet
This is the part most vendors leave out. All of it is true as of the date below.
| Certification or control | Status |
|---|---|
| SOC 2 report | We do not have one. We will not describe a report we do not hold, and we will not use the word compliant for something we have not been examined on. If you need one for procurement, we will tell you plainly that it does not exist yet |
| Signed data processing agreements | In progress, not complete for every provider listed above. We will not claim they are all in place until they are |
| Independent penetration test | Not yet done |
| HIPAA or FERPA compliance | We do not claim either. FERPA binds schools, not vendors like us, and the school official designation is the district's to make. We act on your own access to your child's information, with your permission |
| End to end encryption | We do not claim it. To write a reply, our systems have to read your message, which means we hold it in readable form |
| Accessibility | The public pages are plain HTML: every word of the content is there before any script runs, so the site works without JavaScript. The pages are built to WCAG 2.2 AA (contrast, focus visibility, landmarks, labels, touch targets, reduced motion). We have not completed a formal third-party audit |
| Compliance certifications (HITRUST, ISO) | None held |
What we do have
- This page, which names the encryption we use and the things we cannot do.
- A privacy policy with a retention schedule and the same subprocessor list.
- A published vulnerability disclosure policy with safe harbour for good faith research, and a machine readable security.txt.
- A consent gate, a fill and submit split, and a confirmation requirement that are enforced in code.
Report a security issue
Report it through our contact form. We will acknowledge your report, tell you what we think, and fix what is real. We will not threaten or pursue someone who reports a problem in good faith. The full policy, including what is in scope and what we ask of you, is in our vulnerability disclosure policy.
Last reviewed: September 2026. If any statement here stops being true, we change the page. A security page that lags behind the system is worse than no security page.