Security & Compliance

We take the responsibility of handling school data seriously. Here is an overview of our security practices, infrastructure, and compliance standards.

Privacy-First Design

School Conference Go is built with student data privacy as a core principle. We follow best practices aligned with FERPA and COPPA guidelines to help schools protect student information.

  • We collect only the minimum data necessary for scheduling conferences.
  • We never sell, rent, or trade student or parent data to third parties.
  • Schools retain full ownership and control of their data at all times.
  • No advertising or tracking—your data is never used for marketing purposes.

Data Encryption

All data is encrypted in transit using TLS 1.2+ (Transport Layer Security) and at rest using industry-standard AES-256 encryption. Your passwords and sensitive tokens are hashed and salted using bcrypt.

Secure Infrastructure

Our application is hosted on secure, SOC 2 compliant cloud infrastructure. We utilize automated backups and redundant systems to ensure high availability and data durability.

Access Control

Access to production data is strictly limited to authorized engineering staff on a need-to-know basis. We employ role-based access control (RBAC) within the application to ensure teachers only see data relevant to them.

Data Minimization

We only collect the data necessary to facilitate scheduling (names, emails, basic student info). We do not collect sensitive data like social security numbers, health records, or grades.

Have security questions?

If you are a district administrator requiring a specific vendor assessment or DPA (Data Privacy Agreement), please contact our team.

Contact Security Team →