IT Director

Your questions have direct answers.

No marketing language here. You're evaluating a system that will hold student records. You need to know it's secure, compliant, and compatible with what you run. Here are the answers.

You've seen what happens when a school rushes a software decision. The demo impresses, the Head is keen, and six months later you're handling a breach, a FERPA question, or a system that integrates with nothing.

Your job is to prevent that. Your school's data is an institutional asset, and most SIS contracts make it expensive to leave: proprietary formats, limited exports, migration positioned as a reason not to switch. That's not a feature. It's leverage.

We built Rekods with those questions in mind from the start. The audit logging, access controls, data portability, and compliance architecture are core to how the system was designed.

Built secure from the start.

Two-gate authorization

Role access to the data domain, then entity scope, checked on every sensitive request.

Tenant isolation at the data layer

Every query scoped to your school from the token, never client input.

Append-only audit logging

Every access and change to sensitive data recorded: who, what, when.

TLS in transit, encryption at rest

Industry-standard encryption throughout; secrets stay server-side.

Stytch B2B authentication (JWT)

Authentication handled by Stytch, server-side and verifiable.

Never used to train external AI

Your data serves your school only, never pooled, sold, or used for training.

Full export any time, no lock-in

Standard formats, no exit fees, no data-hostage clauses.

Read our full security posture →

Questions answered.

Are you SOC 2 certified?

Not yet, and we won't claim it until earned. We're building toward SOC 2 Type II and implementing the underlying controls. We'll share our current posture in detail and a committed timeline. A certification is evidence of good practice, but it isn't the same as being secure. Some of the worst breaches in education hit large, fully certified vendors.

What happens to our data if we leave?

Full export in standard formats any time, no exit fees, no data hostage clauses.

Do you use our data to train AI?

No. Never sold, never shared with advertisers, never used to train external models, never pooled across schools.

Will you sign a DPA?

Yes. Send your template. We treat it as the baseline of doing business with schools, not an obstacle.

Who are your subprocessors?

Xano for backend and database, Stytch for authentication, AWS for storage, Anthropic for AI, SendGrid for email, and Firebase for push. Compliance documentation for each is available on request.

How do you handle a security incident?

We notify your school promptly, with specifics, support your own notification obligations, and never go quiet or downplay it. You hear it from us, fast, with detail.

Where does our data physically live?

Data residency options, EU, US, or regional, are available on Enterprise, so you can meet the rules your region or authority requires.

Whatever your role, Rekods speaks your language.

Bring your hardest questions.