SEMFAS — Special Education Management For Faculty And Student Success

Security & Compliance

Last reviewed August 30, 2026

Regulatory framework

SEMFAS is built with the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g; 34 CFR Part 99) and New York Education Law § 2-d in mind. Whether those specific laws apply to a given school's use of SEMFAS depends on that school's own funding and status, and is a question for the school's own legal counsel — this page describes the technical safeguards in place, not a legal compliance determination.

Data protection standards

Data is encrypted in transit (TLS 1.2 or higher) between your browser and our servers. Data at rest is encrypted by our hosting and database providers as part of their own infrastructure.

Access controls

Access follows a role-based, least-privilege model, with permissions assigned individually by role and function. Passwords are never stored in plain text — only as one-way cryptographic hashes that can't be reversed. Staff can optionally require a second step at sign-in — a one-time code sent to their email, in addition to their password. Sign-ins, changes to records, and views of the most sensitive record types are logged for audit purposes; a record of who has merely viewed a document is not yet kept for every document type.

Monitoring

An independent uptime monitor (UptimeRobot) checks that the site is reachable every 5 minutes and alerts the administrator immediately if it isn't. Application errors are automatically reported to an error-tracking service (Sentry), configured so that student names, contact details, and clinical content are never included in what it captures — only that an error happened, and roughly where.

Independent review

SEMFAS has undergone an independent third-party security audit, which found no security issues.

Data retention & deletion

Records are kept until an administrator chooses to delete them. SEMFAS surfaces opted-out student records for review after a configurable number of years, but nothing is deleted automatically — the decision is always made by an administrator.

Questions

For questions about data handling, contact your administrator directly.