IT Director
No marketing language here. You're evaluating a system that will hold student records. You need to know it's secure, compliant, and compatible with what you run. Here are the answers.
You've seen what happens when a school rushes a software decision. The demo impresses, the Head is keen, and six months later you're handling a breach, a FERPA question, or a system that integrates with nothing.
Your job is to prevent that. Your school's data is an institutional asset, and most SIS contracts make it expensive to leave: proprietary formats, limited exports, migration positioned as a reason not to switch. That's not a feature. It's leverage.
We built Rekods with those questions in mind from the start. The audit logging, access controls, data portability, and compliance architecture are core to how the system was designed.
Role access to the data domain, then entity scope, checked on every sensitive request.
Every query scoped to your school from the token, never client input.
Every access and change to sensitive data recorded: who, what, when.
Industry-standard encryption throughout; secrets stay server-side.
Authentication handled by Stytch, server-side and verifiable.
Your data serves your school only, never pooled, sold, or used for training.
Standard formats, no exit fees, no data-hostage clauses.
Not yet, and we won't claim it until earned. We're building toward SOC 2 Type II and implementing the underlying controls. We'll share our current posture in detail and a committed timeline. A certification is evidence of good practice, but it isn't the same as being secure. Some of the worst breaches in education hit large, fully certified vendors.
Full export in standard formats any time, no exit fees, no data hostage clauses.
No. Never sold, never shared with advertisers, never used to train external models, never pooled across schools.
Yes. Send your template. We treat it as the baseline of doing business with schools, not an obstacle.
Xano for backend and database, Stytch for authentication, AWS for storage, Anthropic for AI, SendGrid for email, and Firebase for push. Compliance documentation for each is available on request.
We notify your school promptly, with specifics, support your own notification obligations, and never go quiet or downplay it. You hear it from us, fast, with detail.
Data residency options, EU, US, or regional, are available on Enterprise, so you can meet the rules your region or authority requires.