How It Works Features Security Domains Dashboard Pricing FAQ Log In Request Demo
AI-Enhanced, Expert-Backed

Privacy Compliance Monitoring for Every School District

Student privacy experts with AI-enhanced privacy compliance monitoring technology continuously identify student privacy risks across your school district's entire web presence in hours, not months.

6 Security Domains
Policy-Aware
A–F Compliance Grades

Privacy Compliance Monitoring Is Overdue

School districts face an impossible task. Manually reviewing thousands of web pages, PDFs, images, and data files for student privacy violations simply doesn't scale.

0
Pages per district go unchecked for FERPA violations every year
0
Of districts have at least one undetected FERPA exposure online
0
Average time for a manual compliance audit, with no guarantee of completeness

Student data appears everywhere: board meeting minutes, athletic rosters, honor rolls, IEP committee notes, and spreadsheets linked from staff pages. Traditional approaches can't keep up. SchoolScan can.

Five Steps to Continuous Monitoring

From URL to actionable report. AI-enhanced, policy-aware, and backed by expert review.

Step 1

Crawl

We spider your district's entire web presence, including HTML pages, PDFs, Word docs, databases, images, and spreadsheets.

Step 2

Analyze

AI-enhanced analysis examines unstructured content while statistical methods check tabular data for re-identification risk.

Step 3

Adjudicate

Findings are evaluated against your district's actual privacy policies, reducing false positives automatically.

Step 4

Expert Review

Critical and high-severity findings are reviewed by our staff of privacy professionals who validate results and provide actionable remediation guidance.

Step 5

Report

Get an A–F compliance grade, prioritized findings queue, and exportable dashboards for stakeholders.

Built for Real-World Compliance

Everything you need to find, prioritize, and remediate student privacy risks at scale.

Dual-Pipeline Analysis

AI-enhanced reasoning for unstructured documents like HTML, PDF, and Word files, combined with statistical disclosure avoidance for spreadsheets and CSVs. Two methods, one comprehensive result.

Policy-Aware Adjudication

Automatically discovers and parses your district's privacy policies to classify findings as compliant, conditional, or confirmed violations. No more false alarms on directory information.

8-Criterion Scoring

Multi-criteria decision analysis weighs severity, volume, accessibility, population sensitivity, staleness, and more to produce institution-level A–F grades and domain scores.

6 Security Domains

Comprehensive coverage across direct PII, indirect re-identification, directory info mishandling, education records, metadata leakage, and vendor exposure.

Cost-Optimized

A smart two-stage triage model routes only flagged content for deeper analysis. At only $1,200/month for continuous district-wide monitoring, versus tens of thousands for a one-time audit, or hundreds of thousands for a single breach.

Dashboard-Ready Output

Export compliance data to Power BI, generate prioritized review queues, and produce narrative reports ready for board presentations or federal auditors.

Expert-Backed Findings

Critical findings don't just get flagged — they're reviewed by privacy professionals who validate results, reduce noise, and provide specific remediation guidance tailored to your district.

Six Dimensions of Student Privacy

SchoolScan examines every document across six distinct security domains. Click any card to learn more.

Direct PII Exposure

Student names linked to non-directory records like grades, disciplinary actions, or health information.

Example: Board minutes listing "Jane Doe, suspended 3 days for disciplinary incident" published on the district website.

Critical Severity
Indirect Re-identification

Combinations of quasi-identifiers that can identify students without using their names.

Example: A report showing "Grade 4, Female, English Learner, Free Lunch" in a school with only one matching student.

Critical Severity
Directory Info Mishandling

Directory information published beyond the scope designated in the district's annual FERPA notice.

Example: Student phone numbers published in a school directory when the district only designated name and grade level.

High Severity
Education Records

IEP/504 plans, grades, assessment data, and disciplinary records exposed on public-facing pages.

Example: A linked PDF containing IEP meeting notes with student names and disability classifications.

Critical Severity
Metadata Leakage

PII embedded in document metadata, Open Graph tags, file properties, and hidden form fields.

Example: A PDF's author field containing "jdoe_IEP_review" or og:image tags revealing student photos.

Medium Severity
Vendor Exposure

Student data exposed through third-party EdTech platforms, SSO portals, and embedded widgets.

Example: A class roster visible through an improperly configured LMS embed on the school's public page.

High Severity

Compliance at a Glance

Every scan produces an interactive compliance dashboard with grades, domain breakdowns, and a prioritized review queue.

B
Overall Compliance

Domain Scores

Direct PII92%
Re-identification78%
Directory Info85%
Education Records95%
Metadata70%
Vendor Exposure88%
247
Pages Scanned
12
Findings
3
Critical
2.4h
Scan Time

Priority Review Queue

Finding Domain Severity Status
Student SSN in board minutes PDF Direct PII Critical Violation
IEP notes linked from staff page Education Records Critical Violation
K-anonymity risk in enrollment CSV Re-identification High Review
Student photos in og:image tags Metadata Medium Conditional
Phone numbers beyond policy scope Directory Info Medium Compliant

Designed for Education

Built and operated by privacy professionals for the unique compliance needs of K-12 education.

District A County Office State Agency District B District C
★★★★★

"SchoolScan found three FERPA exposures in our board minutes that we'd missed for over two years. The policy-aware adjudication saved us dozens of hours we would have spent chasing false positives."

SM

Sarah M.

Compliance Officer, Unified School District

★★★★★

"We used to spend months on manual audits. SchoolScan covered our entire web presence in under 3 hours and gave us a clear, prioritized action plan with letter grades by domain."

JR

James R.

IT Director, County Office of Education

★★★★★

"The k-anonymity analysis on our published data files was eye-opening. We had no idea our enrollment reports could re-identify individual students."

LK

Lisa K.

Data Privacy Coordinator, State DOE

FERPA Aligned
Privacy by Design
Data Never Retained
Expert-Reviewed Findings

Compliance That Pays for Itself

At $1,200 per month per district, SchoolScan replaces manual audits that cost tens of thousands and delivers results in hours.

Manual Audit vs. SchoolScan

MetricManual AuditSchoolScan
Time to complete3–6 months2–4 hours
Annual cost per district$15,000–$50,000$14,400/yr ($1,200/mo)
Pages coveredSample only100% of pages
Metadata analysisRarely doneAutomatic
Statistical re-ID riskNever doneK-anonymity analysis
Policy contextManual lookupAuto-adjudicated
Repeat scansStart overIncremental (changed pages only)

ROI Calculator

See how much you save with AI-enhanced compliance monitoring.

Number of districts 1
$1,200
Monthly Cost
$14,400
Annual Cost
$10,600
Est. Annual Savings
100%
Page Coverage
Request a Demo

Common Questions

Privacy compliance monitoring continuously reviews your district's public-facing web content to find student personally identifiable information (PII) that may be exposed. While primarily focused on FERPA (Family Educational Rights and Privacy Act), SchoolScan also identifies broader student privacy risks across HTML pages, PDFs, Word documents, spreadsheets, and metadata throughout your entire web presence.
SchoolScan crawls your district's publicly accessible website, the same pages any parent or community member can already see. We respect robots.txt directives and crawl at a pace that won't affect your site's performance. No credentials or internal access required.
SchoolScan extracts and analyzes content from HTML pages, PDF documents (including scanned PDFs via OCR), Microsoft Word documents, Excel spreadsheets, and CSV files. It also examines document metadata, Open Graph tags, and hidden form fields for potential PII leakage.
SchoolScan uses a two-stage AI-enhanced pipeline. A fast triage model filters documents first, then a deep analysis model extracts detailed findings with confidence scores. Policy-aware adjudication reduces false positives by evaluating findings against your district's actual privacy designations. Critical findings are also reviewed by our staff of privacy professionals before delivery, ensuring accuracy and actionable remediation guidance.
Yes. SchoolScan only accesses publicly available content, data that's already visible to anyone on the internet. Analysis results are encrypted in transit and at rest. No student data is retained after your compliance report is delivered, and scans run in isolated cloud environments that are destroyed after completion.
A typical district scan of 100 to 500 pages completes in 2 to 4 hours. Larger districts with thousands of pages may take longer. Follow-up scans are faster because SchoolScan only re-analyzes pages that have changed since the last scan.
Yes. SchoolScan exports compliance data in CSV format for Power BI and other business intelligence tools, JSON for programmatic integration, and Markdown narrative reports for stakeholder presentations. The prioritized review queue integrates with your existing compliance workflows.
SchoolScan delivers a prioritized review queue ranked by severity. Each finding includes the exact location, PII type, severity score, policy context, and recommended remediation steps. For critical and high-severity findings, our privacy professionals provide expert-reviewed guidance and can assist your team directly with remediation. Once issues are addressed, run a re-scan to confirm they're resolved.

Ready to Protect Your Students' Privacy?

Get a comprehensive privacy compliance scan of your district's web presence, including FERPA and beyond. Results in hours, not months.