D
DetermiNext
Security & Privacy

Student Data is a
Responsibility, Not a Resource.

DetermiNext is built around one principle: the only people who should ever access a student's information are the teacher and the student themselves.

🔒No personal data sold
🤖AI never trains on your data
🏫Teacher-controlled access
📋FERPA-aligned design
Data Collection

We collect the minimum needed
for IEP transition planning.

Every field we store exists to serve the student's IEP. If it doesn't belong in a transition plan, it doesn't belong in our database.

What we collect

  • Student first and last name — for report labeling only
  • Class standing: freshman, sophomore, junior, or senior
  • Assessment responses across the PINS domains
  • Selected career interest(s) at assessment completion
  • School year and section for teacher roster filtering

What we never collect

  • Student email address or phone number
  • Date of birth or Social Security Number
  • Health records, diagnoses, or disability classifications
  • Photos, biometrics, or location data
  • Behavioral records or disciplinary history

No student account creation required. Students enter using a teacher-generated username and one-time access code. They never need an email address, a password, or an account of any kind.

Data Storage

Your data lives in your deployment.
Not ours.

DetermiNext is a single-instance deployment. Your school or district runs its own copy of the platform — student records never leave the environment you control.

🏛️

District-controlled

Data stays within the environment your district controls. No third-party cloud database holds student records.

🚫

No data sharing

We never share, sell, license, or transfer student data to any third party for any purpose.

🗑️

Right to delete

Teachers can remove students at any time. All reports and assessment data tied to that student are removed with them.

Student Access

Teachers control who gets in.
Full stop.

There is no open enrollment, no self-registration, and no way for a student to access another student's assessment. Every access point is teacher-created.

Teacher creates a launch

Generates a unique access code scoped to that student only.

Student enters username + code

No email, password, or account needed. Access is strictly credential-based.

Teacher revokes or closes access

Access can be removed instantly. Reopen and reassess require deliberate teacher action.

No cross-student visibility

A student can only see their own assessment and their own report — nothing else.

AI & Privacy

Our AI generates reports.
It does not learn from them.

We use Google's Gemini API to generate personalized plans. Here is exactly how we handle that interaction — nothing is hidden.

AI runs server-side only

All requests to Gemini are made from our backend server. Your browser never directly contacts the AI. API keys and model prompts never leave the server.

Not used for model training

We use Gemini under usage policies that prohibit using input data for training. Your students' responses are never fed back into any AI system.

Minimal data in AI prompts

Only the PINS assessment responses and career selections are sent to the AI. No names, IDs, or other PII are included in the prompt payload.

Teacher reviews all output

AI-generated content is a starting point — not a final document. The teacher downloads, reviews, and owns every report. Nothing is auto-submitted to any school system.

D
Powered by Gemini AI — server-side only
Compliance & Design Intent

Built with FERPA and IDEA
in mind from day one.

DetermiNext is purpose-built for IDEA Indicator 13 IEP transition planning. Our data model and access controls reflect the compliance obligations special educators work within every day.

FERPA-aligned

Student education records are controlled by the teacher and accessible only within the deployment. No third-party access without explicit authorization.

IDEA Indicator 13

Output is structured around measurable postsecondary goals, transition services, and student-centered career exploration — the core Indicator 13 components.

No targeted advertising

Student data is never used for advertising, profiling, or any commercial purpose beyond operating the platform for the school.

Teacher ownership

All reports, plans, and student data belong to the teacher's school instance. There is no vendor claim to the content you generate.

Security Roadmap

Where we are today,
and where we're headed.

We believe in being transparent about both our current state and the steps we're actively taking to harden the platform.

Live now

Server-side AI with no client key exposure

Gemini API keys and prompt logic live on the backend only. The frontend never has access to AI credentials or raw model prompts.

Live now

Teacher-gated student access

Students access the platform only through a teacher-issued code. There is no open registration or self-signup path.

Live now

Single-instance deployment

Each school or district deployment is isolated. There is no shared database where one district's data could affect another.

Coming next

SSO via Google Workspace and Microsoft 365

Teachers will sign in with their district-issued account, enabling district-level identity management and eliminating separate credentials.

Coming next

Multi-tenant architecture with district-level isolation

Support for multiple districts in one deployment, with strict data boundaries between tenants and admin-level visibility into each district's data.

Coming next

Encryption at rest and in transit + audit logs

All student data encrypted at rest in the production database, in transit via TLS, with audit logs recording all data access events.

Questions about security
or compliance?

If you're a district administrator evaluating DetermiNext or have specific compliance requirements to discuss, we're happy to walk you through the details.