Access controls by role
System and tenant actions are gated by claim-based RBAC to limit access by responsibility.
PTA.AI is designed so parent leaders can move quickly without compromising safety. We apply role-based access controls, encrypted data handling, continuous auditing, and incident-ready operations from intake through live deployment.
Policy radar
Structured for quick board review and deep legal/compliance reference.
Version
v2.1
Sections
6
Policy actions for Security policy
Material update v2.1
Expanded control-domain documentation, incident response flow, and shared-responsibility matrix.
System and tenant actions are gated by claim-based RBAC to limit access by responsibility.
Traffic is protected in transit and platform data is stored with modern encryption standards.
Administrative and policy-sensitive actions are recorded for review and accountability.
Background jobs and release workflows are designed to be idempotent and replayable.
Security events follow a documented triage, containment, and communication path.
Product scope is intentionally designed to avoid collecting student academic records.
Our controls are grouped by practical operating domains so boards, volunteers, and district reviewers can evaluate posture clearly.
Role-scoped permissions, session controls, password policy enforcement, and optional MFA paths for elevated accounts.
Structured validation, protected admin routes, and constrained mutation pathways for high-impact workflows.
Tenant-scoped records, controlled storage access patterns, and predictable data lifecycle rules.
Queue and release controls, environment segregation, and explicit audit logging for critical actions.
Security decisions prioritize school operations, privacy boundaries, and recoverability.
When anomalies are detected, we follow a defined process to reduce impact and keep stakeholders informed.
March 4, 2026 - Security policy redesign
Expanded controls, operations, and shared responsibility sections.
January 15, 2026 - Baseline publication
Initial policy publication for marketing and compliance reference.
Use the channels below for suspected incidents, urgent access concerns, or district review coordination.