Access control
Granular RBAC across student, parent, school, insurer, and agency roles.
Role-based access, audit logs, encryption in transit and at rest, and a SOC 2-aligned control program.
Granular RBAC across student, parent, school, insurer, and agency roles.
Sensitive actions are logged for investigation and compliance.
TLS in transit and encrypted storage for sensitive records.
CSRF protection, rate limits, MFA, and trusted-device controls.
Consent gates and least-privilege data sharing defaults.
Security questionnaires and evidence packs available on request.