Security and privacy

Trust should be visible in the architecture.

Sensitive reporting requires clear technical boundaries: what is collected, who can see identity, where data runs, what AI may process, and which decisions always remain human.

01 / Protected by default

Separate identity from incident facts.

An anonymous web report does not store a case-level IP address or device fingerprint. A claim code lets the reporter write back without putting their name on the record.

When a reporter chooses to disclose identity, field-level permissions restrict access to the people with a legitimate need to know.

02 / Security model

01

Least-privilege access

Control visibility by role, organization, location, incident type, conflict status, and specific sensitive fields.

02

US school deployment

Retention, disclosure, and access rules for a US school. The current offer is anonymous web reporting for K–12 schools across the US.

03

Immutable history

Maintain an append-only record of assignments, access, evidence, decisions, approvals, and status changes.

04

Governed AI context

Exclude prohibited data from model context and define which AI capabilities are available by sensitivity and region.

05

Human decision gates

Require people to authorize high-consequence actions including dispatch, discipline, disclosure, and final closure.

06

Reviewable controls

Map your incident policy to operational permissions, playbooks, deadlines, evidence requirements, and approvals.

03 / Security review

Bring your requirements before you bring your data.

We welcome architecture, privacy, procurement, and compliance review early in the conversation. We will distinguish available controls from roadmap items and deployment-specific commitments.

Start a security conversation

K–12 schools

Request a school portal.

Campus is $99 per campus each month. A district is $599 a month for up to 25 campuses. The page and QR code are ready the week you agree.

Request a portal