Security
We keep a written security program, based on the NIST Cybersecurity Framework, and review it at least once a year and after any incident. A school may ask us for a summary.
How we protect data
- Schools are kept apart. The database itself limits each person to their own school’s data, and staff see only what their role allows. Automated tests check this before every release.
- Sign-in without passwords. Sign-in is by Google or a one-time emailed code. Repeated attempts are blocked.
- Encryption. Data is encrypted while it travels and while it is stored, including backups.
- Limited access. Only people who need it can reach our systems, with strong sign-in protection.
- A record of changes. Changes to children’s records, classrooms, and staff roles record who made them.
- Only what we list. We collect only the data the Privacy Policy lists, and use only the outside services we list.
If something goes wrong
We contain the problem, find out what was affected, and notify each affected school within 72 hours of confirming a breach of its data. We then fix the cause and update our program.
Reporting a security problem
Report a suspected security problem to privacy@aprative.com. We will confirm we received it and tell you what we find. We will not take legal action against anyone who reports in good faith, does not access or change other people’s data, does not disrupt the service, and gives us reasonable time to fix the problem before telling others.
Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-09-25 | First version for the pilot. |