Now enrolling founding districts for the 2026–27 school year · Limited cohort
Regulations & evidence

Built to answer your auditor, your board, and your parents

Student-data law is not a footnote in our terms of service — it's the shape of the product. Every regulation below maps to specific controls, and every control produces exportable evidence.

FERPA

Education records, protected

Student conversations are treated as protected records: role-based access decides who in your district may review them, every access is itself logged, and data handling follows the school-official framework your DPA defines. Parents' inspection rights are supported through your district's established process.

COPPA

Scoped honestly at 13–17

KeepChatSafe is designed for students 13 and older, with school identity — not self-reported birthdays — as the age gate. Deployments for under-13 students carry additional consent and data-retention duties; we scope those separately with your counsel rather than blurring the line.

SOPIPA · California

No sale. No ads. No profiling.

No sale of student data, no targeted advertising, no non-educational profiling, and no use of student conversations to train AI models. The statutory prohibitions are product invariants, not policy promises.

AB 1584 · California

Contract clauses, pre-drafted

Our data-privacy agreement template is drafted to AB 1584's required clauses: district ownership of student records, permitted-use limits, security procedures, breach notification, and certified deletion at contract end.

CIPA · Context

Completes your filtering story

Your CIPA web filter governs where students go; KeepChatSafe governs what happens inside the AI conversation your filter can't read. Together they give your board a complete answer about student internet safety — each layer doing the job it was designed for.

AI Provider · Under-18

The layer providers require

Frontier AI providers permit serving minors only with content filtering, monitoring, escalation paths, and age assurance in place — and reserve the right to audit. KeepChatSafe's evidence pack maps our controls to OpenAI's Under-18 API Guidance and Anthropic's guidelines for organizations serving minors, so your deployment stands on documented ground.

Data governance

Where student data lives, and who can touch it

  • Tenant isolationYour district's data sits in its own isolated tenant with database-enforced row-level security — not a shared bucket with a filter on top.
  • District-owned retentionRetention and deletion schedules follow your records policy; deletion is certified, and exports are yours on request.
  • Minimized model exposurePersonal information is redacted before any AI provider sees a message. Student conversations are never used to train models.
  • Fail-closed governanceIf the governance layer is unavailable, requests are refused — content is never sent raw. If the audit log can't be written, the action doesn't run.
  • Logged administrative accessEven privileged review of student conversations requires a role, a reason, and a durable log entry your auditors can see.
Educators reviewing information together on a tablet
Your records office, your wellbeing team, and your IT department each get the controls — and only the controls — their role requires.
Security review

The packet, before the pitch

Serious districts review before they pilot. Our security review packet is available under NDA ahead of any commercial conversation, and includes:

  • Architecture & data-flow diagramsEvery hop a student message takes, and what happens to it at each one.
  • Subprocessor list & model-provider termsWhich AI providers student traffic may reach, and the minor-serving terms each operates under.
  • Control-to-evidence mappingEach compliance pack, control by control, with how the evidence is produced.
  • DPA draft, incident response & retention scheduleReady for your counsel's redlines — AB 1584 clauses included.
Request the security review packet
Our honesty policy We will never show you a certification badge we don't hold, a customer logo that isn't real, or a capability we can't demonstrate. In a security review you'll get the real answer to every question — including which items are roadmap, and when. We build governance software; being auditable is the whole point.

"Ask us the question you'd ask after the incident. If our answer depends on a slide instead of a log, walk away."

— How we open every CISO briefing

Put our claims in front of your counsel

Request the security review packet, or bring your privacy officer to a briefing. Straight answers, in writing, before any pilot.

Book a district briefing