Trust and security
Built for the records schools can't get wrong.
Pickup records name children and the adults allowed to collect them. Here is how we keep them accurate, private and provable.
No facial recognition
Photos are kept for a person to compare by eye. We never create face templates, and we never match faces. On-device detection only checks that one face is in frame, so the photo is useful.
Tamper-evident records
Each event is signed by the device that captured it with a key that can't leave the device, sealed into a per-site hash chain, and anchored hourly to a public timestamp authority.
Isolation and encryption
Each site's data lives in its own store. Data is encrypted in transit and at rest, with per-site keys for photos, signatures and exports.
Least access
Teachers see their own class and can't export. Parents see their own children. Administrators use a second factor. Every disclosure is logged.
Retention and deletion
Retention follows each state's rules. After it, records keep only an anonymous link in the chain and photos and signatures are deleted. At the end of a contract, a certified deletion.
Schools stay in control
We act for the school as a "school official" under FERPA, sign data privacy agreements, and tell every affected school of a breach within 7 days.
Security questions or a vulnerability to report: privacy@vavr.us. Read our privacy policy.