How we work with a district
- Agreement. We sign the California Student Data Privacy Agreement (CA-NDPA) with each district, including the general offer so any California district may adopt the same terms, and the California and AI addendum.
- FERPA. Beehave acts as the district's school official under 34 CFR 99.31(a)(1)(i)(B): direct control, use only for the authorized purpose, no redisclosure.
- Insurance. Cyber liability and general liability, with the district named as additional insured; certificates on request.
- Questionnaires. Completed K-12CVAT Lite, HECVAT Lite and CIS Controls self-assessment available on request. Signatory to the CISA K-12 Secure by Design pledge.
Practices in place today
- Access limited to legitimate educational interest. Capability engine (src/lib/permissions), org and person scoping (src/lib/scoping.
- No personal information collected online from children. No student-facing route (src/middleware.
- Pupil-generated content. Not applicable: Beehave stores no pupil-generated content (staff record about pupils).
- Breach notification procedure. RUNBOOK-incident-response.
- No targeted advertising. No advertising anywhere in the product; no ad or analytics SDK in package.
- Operator status — Beehave is squarely in scope. Acknowledged.
- No targeted advertising, no profiling, no sale. Nothing in the product advertises, profiles for non-school purposes, or sells.
- Written incident response plan and breach notice contents. RUNBOOK-incident-response.
- Not on the reviewed list; no competitor is either. Fact, not a duty.
- No trackers. No analytics, advertising or third-party scripts; fonts and speech recognition run on your own device.
- Encryption. TLS in transit; encryption at rest at our database and storage providers.
- Security headers. HSTS with preload, a content security policy, and frame denial on every response.
- Sessions and sign-in. Invitation-only accounts; administrative roles sign in through Google with two-step verification; sessions expire after eight hours of use; deactivating a person ends their access within a minute; failed sign-ins are throttled.
Program
- A written information-security program with a named coordinator and an annual risk assessment.
- An incident-response plan: the affected district is notified without undue delay, with the facts it needs to notify parents.
- Backups with point-in-time recovery, and a restore drill on the calendar.
- A data retention schedule, published in our Privacy Policy.
- A monthly compliance audit recorded by the platform administrator, and a build-time check that fails any change that regresses a criterion.
AI
Three optional drafting features use Anthropic's Claude. They are off for every district until written consent is on file; the student's name is replaced by a code before anything is sent; the vendor is contractually barred from training on the data; zero data retention is requested. A clinician signs every document.
Report a security concern
security@beehaveur.com. We acknowledge within two business days.
Subprocessors: /subprocessors · Accessibility: /accessibility