Security & Privacy

Student movement data — handled with care and described honestly.

Ona Pass collects only the fields required for pass workflows. We frame our approach for FERPA-aware US schools, document role-based access, and label what is available in preview and pilot versus what is planned.

🔒 Data minimization 👤 Role-based access 📋 FERPA-aware framing ⚠️ Preview/pilot status documented

FERPA-aware framing

US schools operate under FERPA requirements for student education records. Ona Pass handles student movement data that may constitute directory or education record information depending on context.

Future application development addresses FERPA compliance explicitly — including data handling agreements, retention policies, and school-controlled access. During preview and pilot, we use scoped onboarding with documented demo or verified school data.

We do not present preview or pilot environments as fully compliant production deployments. Schools evaluating Ona Pass should involve their legal and technology teams in any data handling review before pilot participation.

A formal privacy policy and detailed security architecture will be published during later product phases. This page describes our current approach and honest status.

Data minimization

Ona Pass collects only fields required for pass workflows. No unnecessary personal data is collected or displayed.

Core pass fields include:

  • Student name and/or student ID
  • Location data (origin and destination)
  • Timestamps and duration
  • Pass type (Round Trip or One Way) and status

Staff availability settings indicate whether an adult can receive students — without requiring a reason. Where policy permits a "send anyway" action, that decision must be auditable by administrators.

Preview environments use synthetic student names only. Pilot schools verify roster data during onboarding; data scope is limited to participating staff and students.

Role-based access

Staff and administrators see different surfaces designed for their roles — not a single dashboard with permissions layered on top.

Staff (Teachers & Staff) use the Staff Notebook: create passes, view Currently Out for their students, receive inbound passes via Passes To You, and review Today's Log for their own activity.

Administrators use the Campus Clipboard: live campus-wide Currently Out, campus overview, staff directory, rules, and school settings within current scope.

Secure authentication and session management are requirements for production deployment. Preview uses demo sessions; pilot schools receive trial keys with scoped access. Detailed authentication design will be documented before general production rollout.

Preview and pilot status — stated clearly

We label what is available today and what is planned. Schools evaluate better when claims match behavior.

Preview — Public demo with synthetic data. No school credentials. Useful for workflow evaluation by staff, administrators, and IT.

Pilot — Scoped school onboarding with trial keys, typically ten staff, defined support, and a two-to-four-week evaluation window. Real passes with verified roster data.

Production — Requires separate security review, formal privacy policy, authentication design, and deployment pipeline documentation. Not available for general district rollout at this stage.

Production credentials are managed outside the repository. Secrets, tokens, and API keys are never committed to source control. Application deployment at app.onapass.org will follow documented security review.

IT Overview Contact for Security Questions