How ToolBoxAI protects student data with security controls built for K-12 education.
Last updated: 14 September 2026 | Version 2.2
The ToolBoxAI Educational Platform is a game-based learning system built from the ground up with privacy-by-design principles. Our architecture ensures that student data protection is not an afterthought but the foundation of every technical decision we make.
This whitepaper outlines the security measures, compliance frameworks, and operational practices that protect our users. It is intended for school administrators, IT directors, and compliance officers evaluating our platform for adoption.
Every piece of data within the ToolBoxAI Educational Platform is protected using multiple layers of encryption, access controls, and monitoring.
The ToolBoxAI Educational Platform maintains compliance with all major educational data protection regulations. Select a framework below for details.
We meet all FERPA requirements for the protection of student education records. Parents and eligible students have full rights to inspect, amend, and control disclosure of their educational records.
Our controls are designed to meet the 2026 COPPA rule update: verifiable parental consent, data minimization, and strict limits on data collected from children under 13.
Our platform helps schools meet CIPA requirements by providing built-in content filtering, monitoring capabilities, and age-appropriate safeguards for all online activities.
CASE 1.1
Standards alignment and curriculum interoperability
Data subject rights
Data export and deletion requests handled on request
Our multi-cloud infrastructure is designed for resilience, performance, and security across every layer of the stack.
Railway (API) + Vercel (Frontend) + Supabase (Database) with automatic failover and geographic redundancy.
WAF protection, DDoS mitigation, rate limiting on all endpoints, and automatic IP reputation scoring.
Docker images scanned for CVEs on every build. Non-root containers with read-only file systems in production.
Automated Dependabot and CodeQL analysis on all pull requests. Zero tolerance for critical vulnerabilities.
All credentials stored in encrypted vaults. No secrets in code, environment files, or container images.
Structured logging with structlog, Prometheus metrics, Loki log aggregation, and Grafana dashboards.
Our incident response plan is tested quarterly through tabletop exercises and simulated breaches. Every team member knows their role.
Automated monitoring systems detect anomalies. On-call engineer is paged. Initial severity classification is made.
Affected systems are isolated. Threat is contained. Forensic data collection begins. Incident commander coordinates response team.
Root cause identified and eliminated. Systems restored from clean backups. Integrity verification performed across all affected data.
Affected schools and parents notified per regulatory requirements. Transparent communication about impact, actions taken, and preventive measures.
Detailed post-mortem conducted. Lessons learned documented. Security controls updated. Results shared with affected parties.
We welcome security researchers to report vulnerabilities responsibly. Please send details to security@toolboxcity.ai. We commit to:
Our security and compliance team is available to answer questions, provide additional documentation, or schedule a security review call.
security@toolboxcity.ai
Vulnerability reports, security questions, and incident reporting
privacy@toolboxcity.ai
FERPA, COPPA, CIPA inquiries, DPA requests, and audit documentation
privacy@toolboxcity.ai
Data subject access requests, deletion requests, and privacy concerns
support@toolboxcity.ai
Partnership inquiries, sales, and platform demonstrations
This security whitepaper is provided for informational purposes. For the most current information about our security practices, please contact security@toolboxcity.ai. Security infrastructure powered by ToolBoxAI.
© 2026 ToolBoxAI. All rights reserved.