clearAMS / Security & data

Nothing to leak.

Security was a design requirement, not an afterthought. clearAMS holds no student records, no passwords and no banking detail, and every district is walled off from every other.

0student records collected, stored or transmitted
0passwords anywhere in the system
1district reachable per admin credential
2places every dollar limit is checked: browser and server

District isolation

One platform. Hard walls between districts.

Each district is served from its own address with its own data, settings and people. Sessions are tied to the district they were issued for, and an administrator's credential opens exactly one district.

Scoped by addressEvery request is resolved to one district before it touches any data.
Scoped sessionsA sign-in for one district is not valid in another.
Per-district admin keysStored as salted hashes on the district's own record, with no global fallback.
Fails closedA district with no admin configured has no admin surface at all.
Capabilities enforced on the serverWhat a district's plan includes is checked where the request lands, not by hiding a button.
Tiers can't be self-grantedA district's settings carry its tier, never its powers.

What we hold

As little as possible, by design.

clearAMS is a compliance and planning tool, not a financial or student information system. It holds what a plan and its audit trail need, and nothing more.

We hold

  • Plan lines, narratives and amounts
  • Allocation and expenditure totals for planning
  • Staff email addresses on your approved list
  • Review notes, decisions and SSC dates

We never hold

  • Student records of any kind
  • Passwords
  • Bank or account credentials
  • Requisition-level transactions

Your district stays in control

Google sign-in only

Staff sign in with district Google accounts. A Google sign-in alone never grants entry; the person must also be on your approved list.

Documents in your Drive

Plan documents and decks are written to your district's own Google Drive, under your Workspace's sharing rules.

Export and restore

Your data belongs to your district. Snapshot everything to a single file on demand, and restore from it.

Hardened by review

Session expiry, constant-time credential checks, encrypted storage and a strict allowlist of what the server will serve.

An audit trail per plan

Who reviewed it, what they said, what changed between versions and the SSC date that made it official.

Gated releases

Every change to the platform passes an automated suite of checks before it can deploy.

For your IT team

Does clearAMS store any student data?

No. It collects, transmits and stores no student records of any kind.

How do staff sign in?

Through Google sign-in with district accounts. There is no password anywhere in the system. Under a district contract, clearAMS can use your district's own Google sign-in client.

What if the AI check is unavailable?

It fails open. Plans can still be built and submitted, and your reviewer remains the backstop, exactly as without it.

Can we get all of our data out?

Yes. A full export of your district's data is built in, and the same snapshot can be restored.

Can we get a security review packet?

Yes. Contact us and we'll send the technical overview and answer your team's questionnaire.

Questions from
your IT team?

We're glad to go through the architecture, the data we hold and how districts are kept apart.