Security and student privacy

Designed to minimize unnecessary access and storage.

CampusLayer Connect is being designed with FERPA aware district workflows, least necessary access, explicit authorization, and a separation between CampusLayer control data and sensitive provider data.

What the managed control plane can know

  • • CampusLayer account and organization information
  • • Registered devices and device public keys
  • • Connector configuration and health state
  • • Granted CampusLayer capabilities and AI client authorization
  • • Software version and release channel
  • • Sanitized diagnostic events

What Connect does not centralize by default

  • • Raw provider passwords
  • • Raw browser SSO cookies
  • • Raw Skyward session material
  • • Complete provider page HTML
  • • A standing copy of grades, attendance, schedules, or discipline records
  • • Full provider responses simply for diagnostics

District authorization still matters.

Architecture alone does not create a blanket compliance claim. Managed institutional use may require district privacy, security, procurement, contractual, and provider review. CampusLayer is being built to support that process rather than asking individual educators to personally assume those decisions.