Security and Privacy by Design
School security software handles highly sensitive information. SAM is designed around district-controlled processing, data minimization, least privilege, and human review. Product and deployment evidence is evaluated against applicable student-privacy and secure-development requirements. TDR does not claim certification or blanket compliance without a documented assessment.
Student Data Stays on Your Premises
SAM is designed so screening occurs on district-managed systems and student-identifying content is not sent to TDR cloud analysis. This property must be verified for the applicable release and deployment; authorized disclosures remain governed by district policy and law.
- FERPA: Designed to support district-controlled handling of education records and authorized disclosure workflows. Each deployment requires district legal-basis, contract, and privacy review.
- New York Education Law 2-d: Architecture and contract materials are evaluated against applicable requirements. A district-specific Data Privacy Agreement and assessment are required.
- COPPA & PPRA: Where these laws apply, consent, notice, parental-rights, and opt-out requirements must be addressed in the district workflow and release review.
People Decide. Software Assists.
SAM flags and quarantines — it does not punish. Every consequential action involving a student includes human review by your staff. Detection technology narrows the haystack; your administrators and law enforcement make the calls.
Secure by Design
We build to the standards CISA asks software vendors to meet:
- Development practices are derived from the NIST Secure Software Development Framework (SP 800-218). TDR has not claimed a third-party SSDF conformance assessment.
- TDR maintains component inventories and is implementing release-specific software bill of materials (SBOM) generation. Availability, completeness, hashes, provenance, and distribution are stated only for releases whose records verify them.
- Secure defaults: the safe configuration is the shipped configuration.
- Primary application code uses Python, C#, and TypeScript, reducing exposure to common memory-corruption classes. Native dependencies and documented exceptions remain subject to component-level release review.
Vulnerability Disclosure Policy
We welcome good-faith security research on our products.
Report a vulnerability: security@tdrtechnologysolutions.com
We acknowledge reports within 3 business days and keep you informed as we investigate and remediate. Our full policy — scope, safe harbour, response times, and what to do if you encounter student data — is published at tdrtechnologysolutions.com/security/. We will not pursue legal action for good-faith research that respects student privacy, avoids service disruption, and gives us reasonable time to fix issues before public disclosure.