How School Threat Data Flows to Law Enforcement — and How It’s Protected
When a school threat becomes a law‑enforcement matter, every district asks the same fair question: what happens to our data — and is our students' information protected? Here is the exact journey a threat takes from a school inbox to a law‑enforcement case, what is protected at each step, and who stays in control.
The journey — step by step
- SAM detects the threat — on your premises
Screening runs on a server inside your district. Student email and call content are never sent to the cloud to be analyzed. Nothing has left the building yet.
School · on‑premise
- You decide the handoff
By default, a person on your staff authorizes sending a confirmed threat to law enforcement. If your district chooses, it can enable automatic notification the instant a threat is confirmed — your policy, your choice.
School controls
- The Student Privacy Engine strips student data — automatically, before anything leaves
Every student‑identifying detail is removed before a case is sent. This isn't a setting someone can forget; the redaction runs fail‑closed — if it can't verify a clean pass, nothing is sent. The FERPA‑safe path is the only path.
SAM · automatic
- The original stays with you
The full, unredacted message or recording stays inside your district — access‑logged, never transmitted to us, and sealed with a SHA‑256 hash and an independent RFC 3161 trusted timestamp so any later alteration can be proven. Your evidence, in your building.
School · retained locally
- Law enforcement receives a redacted case
Investigators get the email headers, routing metadata, and forensic detail they need to work the case — without student PII. Enough to investigate; nothing that exposes a child.
Law enforcement
- Law enforcement investigates
On the LE side, the case moves through response, credibility, attribution, charging, and disposition — with legal‑process drafting, evidence preservation, and a cost‑of‑threat/victim record for restitution. Coming for pilot agencies: a cross‑agency network that connects officers working the same actor across jurisdictions.
Law enforcement · pilot
- The answer comes back to the school
Law enforcement can make a fast, data‑driven credibility call and advise the school on what to do — often resolving a threat before it disrupts a school day. Every threat also becomes a prosecution record.
School · guidance returned
Who controls what
| The school controls | SAM handles automatically | Law enforcement controls |
|---|---|---|
| Whether and when a threat is handed off · its own data and the local original · which staff have access | Stripping student PII before handoff · building the case file · preserving the original on‑site | The investigation · what it shares with other agencies · charging and disposition |
SAM is designed to keep student‑identifying data within your district — and that is not a setting anyone can switch off. It is not copied into the law-enforcement system — because it stays on-premise, the strictest state's standard is simply how the system works everywhere. Law-enforcement deployments follow 28 CFR Part 23 and CJIS. The two run as separate instances, and information moves between them only through a controlled, one‑way, audited path.
For law‑enforcement & pilot agencies. SAM‑LE takes the case from first response through disposition — legal‑process drafting, evidence preservation, cost‑of‑threat and victim reporting for restitution, and a cross‑agency network being built to connect officers working the same actor. Available for pilot agencies.
TDR Technology Solutions. School data is de‑identified before it reaches the law‑enforcement side; the unredacted original is retained on‑premise in the district. Law‑enforcement capabilities are available for pilot agencies. This page describes how data is handled, not proprietary detection methods.