schoolOS builds agentic AI for operations, not instruction. Every capability is transparent, controllable, and accountable. This page explains how we keep your data, your people, and your decisions protected.

Our agents work on assets, tickets, and procurement. They run on operational data, and only the operational data the work requires. They never run on academic records, behavioral records, or anything that decides a student's outcome.
Because we stay away from high-stakes calls about people, whole categories of bias and equity risk never enter the picture.
The safest data to put an agent on is the data that never judges a child. That is the only data schoolOS touches.
We never use your data to train foundation models. Data residency, retention, and deletion are documented and enforced. We sign standard data privacy agreements without friction, and we stand behind FERPA and COPPA compliance in writing.
Agentic AI acts, so we put guardrails around action. Anything irreversible or high-impact routes to a human for approval. Agents operate inside scoped permissions you control by role.
A complete, timestamped audit trail records what each agent did and why, with plain-language rationale you can defend publicly. Actions can be reviewed, explained, and rolled back. Nothing happens in a black box.
Our agents run on infrastructure and operational data, not academic or behavioral records about individuals. This design choice removes entire categories of bias and equity risk before they can occur.
We hold ourselves to recognized security standards. We publish our practices and name our subprocessors, including the model providers we call. You always know who touches your data.
Adopt our agents alongside the systems you already run. No rip-and-replace required. Your data exports easily and on demand. We earn renewal through value, not by making it hard to leave.
We work in close partnership with districts to meet federal, state, and provincial privacy obligations. Because our agents run on operational data rather than student educational records, your privacy posture with schoolOS is simpler to manage from the start.

We sign district data privacy agreements and operate under your direct control. Student-connected data, like a device assigned to a learner, is used only for the purpose you authorize and honors FERPA's redisclosure limits.

Only authorized district staff create and manage accounts. There is no open registration and no anonymous access. All data use is governed by your district agreement and limited to the operational purpose you authorize.

For districts operating under Canadian privacy law, records stay under your institution's control. We limit use to the purposes you authorize and support access and correction requests, consistent with FIPPA.

We hold ourselves to recognized security standards, publish our practices, and name every subprocessor that touches your data, including the model providers we call. Our security roadmap is shared with district partners on request.