Consulting for Education: Security, Compliance, and Technology
.avif)




FERPA turns on specifics: what counts as directory information, who qualifies as a school official, and when consent is required. We map those rules to the places student records actually live, the SIS, the LMS, and the export files in between, and write policies your staff can follow.
Most districts run security with a handful of people, and universities split it across departments. We scope the work accordingly: training that reaches teachers and registrars, incident plans that name who calls whom, and controls that hold up when under-13 students and COPPA enter the picture.
Research universities carry a second set of obligations: grant agreements now arrive with security riders, and federal data use agreements have teeth. We build the controls those require. And as AI tutoring and proctoring tools reach classrooms, we help you decide what student data they may touch and under what review.