Role-Based Access
Administrators, teachers, and parents receive different visibility. Parents are limited to students linked to their account after school verification (or email match to the roster).
Trust & Security
Built for Institutional Accountability
Asset Pilot EDU supports K–12 technology operations with role-based access, secure sessions, and clear limits on what family accounts can see. We focus on reducing risk and protecting integrity — not impossible guarantees.
Asset Pilot EDU protects school and family information with role boundaries, secure sessions, and Stripe-hosted payments when cards are used. Practices below match how the live product works — not marketing guarantees.
Administrators, teachers, and parents receive different visibility. Parents are limited to students linked to their account after school verification (or email match to the roster).
Portal sessions use HTTP-only cookies. Passwords are stored as irreversible hashes, not plain text.
Production traffic uses HTTPS with HSTS. Database hosting uses provider-managed encryption at rest.
When online pay is enabled, card numbers are entered on Stripe’s pages — not stored in Asset Pilot.
Form signatures, impersonation, and key device actions are logged to support school accountability.
We reduce risk, monitor, and improve controls. No system can honestly promise it is unhackable.
Operational systems are designed to support administrative continuity.
Platform architecture supports restoration planning and continuity processes.
Security and operational processes evolve alongside platform maturity.
Accounts receive only the visibility required for their role — admin, teacher, or parent.
Signatures, impersonation, and key device actions support review and institutional oversight.
The current deployment serves one school’s data. Multi-school tenant isolation is a future product step, not a present marketing claim.
Trust and legal pages explain hosting partners, payments, and parent scoping in plain English.
We process information needed to run devices, repairs, forms, and family portals.
The deploying school remains the custodian of student education records.
Parent accounts see linked children and related devices, repairs, and payments — not the full student roster.
Public policies describe subprocessors (Vercel, Supabase, Stripe when enabled) in plain language.
We do not sell personal information or use student data for unrelated advertising.
These pages describe platform practices for parents and schools. They are not legal advice; schools should consult counsel for FERPA, COPPA, and institutional policy questions.
Questions regarding operational security, governance, or platform practices may be directed to the appropriate contact channels.
security@assetpilotedu.com
Security inquiries
privacy@assetpilotedu.com
Privacy inquiries
legal@assetpilotedu.com
Legal inquiries
Asset Pilot EDU is designed to support institutional technology operations through structured workflows, operational accountability, and transparent governance practices.