Demonstration data only. Do not enter real student, child, or family information. This pilot runs on placeholder data until the required privacy and policy authorizations are granted.

For Reviewers

Trust & Compliance

One place that answers the questions a privacy office, legal team, or technical reviewer asks before approving a tool that handles student and family data. Built for review under ATIPPA, FIPPA, and PIPEDA. We would rather over-share here than have you guess.

Last updated: June 2026

Data residency

InclusionWorks is built for Canadian data residency. For the pilot, production hosting and the database are being provisioned in Canadian regions, and all data is encrypted in transit and at rest, with database connections using TLS. The optional AI analysis feature is disabled and will not be enabled until Canadian-resident AI hosting (AWS Canada, ca-central-1) is in place. That gate is enforced automatically at startup: the application refuses to run the AI engine for real data without an explicit Canadian-residency acknowledgement.

No model training on student data

Student data is never used to train machine-learning models. The default analysis engine is a deterministic, rules-based engine that makes no external network calls. The optional AI engine stays off by default; when it is enabled (only after Canadian-resident hosting and the proper data agreements are in place), inputs are used solely to produce that one analysis and are not retained for, or used in, model training by us or our providers. Every analysis records which engine produced it, so a reviewer can always tell rules-generated from AI-generated output.

Retention and deletion

We keep information only as long as needed to deliver the service and to meet legal and audit obligations, on a per-data-class retention schedule agreed with the district. Deletion is built in, not promised: a school administrator can erase a student and every derived record in one action. Erasure removes the personal data; it deliberately does not rewrite the public audit ledger, because that ledger carries no personal information (see below).

Access, correction, and export

Subject to applicable law, individuals can access, correct, and export their information. A school administrator can export a student’s complete record as a downloadable file in-tenant. Every export and erasure is itself logged to the tamper-evident ledger under a non-reversible alias.

Breach response

We maintain a written breach-response plan covering detection, containment, assessment, notification, and post-incident review, including the notification timelines expected under ATIPPA and to the Office of the Information and Privacy Commissioner for Newfoundland and Labrador. The full plan is available to reviewers on request.

Security architecture

  • Passwords are bcrypt-hashed; plaintext is never stored or sent to the browser.
  • Sessions are server-side, httpOnly cookies; only a hash of the session token is stored.
  • Optional two-factor login (authenticator app) with single-use backup codes.
  • Role and tenant scoping on every request; one district or role can never read another’s data.
  • Login rate limiting and account lockout; same-origin (CSRF) protection on every change.
  • Strict security headers, and the startup guard refuses to run misconfigured in production.

Tamper-evident audit ledger

Every concern, response, and status change is appended to an append-only, cryptographically signed ledger. Anyone, with no login, can recompute the chain and detect any tampering. The public ledger contains no personal information: only role labels, generic summaries, opaque aliases, and one-way hashes. Verify the ledger yourself.

Sub-processors

We use a small number of service providers strictly necessary to run the platform, each under contractual data-protection obligations: cloud hosting and managed database, transactional email delivery, and (only when explicitly enabled for non-real data) an AI analysis provider. A current sub-processor list is available to reviewers on request.

Privacy Impact Assessment support

We support the PIA process early rather than waiting for it. We can provide a data inventory, a data-flow description, the retention schedule, our STRIDE threat model, and this security posture in a single pack to give your privacy analyst a running start.

Demonstration data only

Until privacy and legal sign-off, and any required policy decision, are granted, the platform runs in demonstration mode on placeholder data, shown by the notice at the top of every page. We do not move to real records until the authorizations are in place.

Contact

Reviewer and privacy questions: info@gnosisethical.com. See also our Privacy Policy.