Security & Compliance

Built for the Strictest District in Your State

School security software handles the most sensitive data a vendor can touch. SAM is designed to keep student data within your district — and that is not a setting anyone can switch off — the strictest state’s standard is how the system is built to work everywhere. Here is exactly how we handle it.

Student Data Stays on Your Premises

SAM processes student data — email, call records, names — on servers inside your district. Nothing that identifies a student is transmitted to the cloud for analysis. This isn’t a configuration option a vendor can get wrong; it’s how the system is built.

  • FERPA: No education records leave the school. Disclosures happen only through your district’s own processes.
  • New York Ed Law 2-d: Data Privacy Agreement available; our architecture satisfies the data-minimization and security requirements out of the box.
  • COPPA & PPRA: SAM supports district consent workflows for students under 13 and PPRA-compliant opt-out.

People Decide. Software Assists.

SAM flags and quarantines — it does not punish. Every consequential action involving a student includes human review by your staff. Detection technology narrows the haystack; your administrators and law enforcement make the calls.

Secure by Design

We build to the standards CISA asks software vendors to meet:

  • Development aligned to the NIST Secure Software Development Framework (SP 800-218).
  • A software bill of materials (SBOM) — every component, version, and source — available to customers for every release.
  • Secure defaults: the safe configuration is the shipped configuration.
  • Memory-safe languages for all product code.

Vulnerability Disclosure Policy

We welcome good-faith security research on our products.

Report a vulnerability: security@tdrtechnologysolutions.com

We acknowledge reports within 3 business days and keep you informed as we investigate and remediate. Our full policy — scope, safe harbour, response times, and what to do if you encounter student data — is published at tdrtechnologysolutions.com/security/. We will not pursue legal action for good-faith research that respects student privacy, avoids service disruption, and gives us reasonable time to fix issues before public disclosure.