Security and privacy
This page explains the privacy commitments in our policies and the product controls schools actually use: roles, optional 2FA, school scoped access, QuickBooks Payments, audit exports, and admin gated file backups. No invented certifications or fake school stories.

Policy commitments
These statements track the published privacy and cookie policies. They are commitments about how Corebytes LLC runs DriversEdPro, not marketing badges from outside auditors.
Corebytes LLC does not sell, trade, or rent personal information to third parties for independent commercial marketing lists.
Data is encrypted in transit and at rest where appropriate for the cloud architecture, including HTTPS for browser sessions.
Accounts use authentication, role based portals, and school scoped database access so people only reach the records their role allows.
The privacy policy lists regular security reviews, dependency maintenance, confidentiality expectations, and incident response procedures.
Access model
Users sign in with email and password. Optional authenticator based 2FA adds a second step. Student, instructor, assistant, and school admin portals stay separate, with school data protected by row level security.
Authenticator app enabled
Backup codes available
After password entry, the next prompt asks for a 6 digit code from the authenticator app.
Student
Portal, drives, payments, learning
Instructor
Calendar, drives, messaging, classes
Assistant
Restricted faculty portal
School admin
Faculty, billing, exports, backups
Supabase Auth handles sign in, email confirmation, and password reset recovery links.
TOTP apps and backup codes can protect an account after the password step when enabled.
Students, instructors, assistants, and school admins land in different experiences with different tools.
Database row level security keeps school records tied to the school context for that account.
Payments
Online card processing runs through Intuit QuickBooks Payments. DriversEdPro stores payment outcomes and balances for school workflows, not full card numbers as a PAN vault.
Schools connect QuickBooks Online so checkout can charge cards through Intuit.
Card entry and storage for online charges are handled by the payment processor, not kept as full card numbers in DriversEdPro.
Successful charges update student balances and can gate drive scheduling based on school payment rules.
Successful charges create sales receipts in QuickBooks so accounting and school balances stay aligned.
QuickBooks Payments
Card processing with Intuit
Full card numbers are not stored as a DriversEdPro PAN vault
Student balances update after successful charges
Sales receipts sync into QuickBooks
School controlled records
School admins can export operational CSVs and back up school uploaded files. Backup downloads require admin password confirmation. These tools help schools keep their own copies of activity and files.
2 selected
Audit log
Drive sessions
Student roster
Payments
Export CSV records of changes to grades, drives, payments, and settings.
Download drive sessions, signatures, student and instructor rosters, fleet, payments, and attendance exports.
Back up school files to a ZIP download or to connected Google Drive, OneDrive, or Dropbox.
Sensitive backup download paths ask the school admin to confirm with their password before the job runs.
Download ZIP
Google Drive
OneDrive
Dropbox
Admin password confirmation protects backup download paths
Scheduling data
Smart scheduling tools such as room occupancy, student drive preferences, and FIFO auto schedule live in the same school system as payments and messaging. Those records follow the same role and school scoping rules as other school data.
Weekly room occupancy and conflict checks help keep in person and online rooms from overlapping inside the school calendar.
Preferred days and times stay on the student record so open slots can be offered in preference order.
When a slot reopens, the preference queue can auto schedule the next matching student, with confirmation when required.
Instructors, assistants, students, and admins only see the scheduling surfaces their roles allow within their school.
Operational data inside the school tenant
Room 101 occupancy
School scoped calendar block
Drive preferences
Tue / Thu after 3:00 PM
Auto schedule queue
FIFO fill when a slot opens
Education privacy
Where FERPA applies to a school's education records, the privacy policy describes how DriversEdPro supports school controlled handling. This is a policy commitment, not a third party certification badge.
Schools decide who enrolls, which staff get access, and how student records are used inside their program.
Processors such as hosting, email, SMS, and payments support product delivery. They are not treated as marketing list buyers.
The cookie policy states we do not sell personal information collected through cookies and do not run retargeting ad networks on that data.
Privacy and cookie pages remain the authoritative wording for disclosures, retention, and legal process responses.
Honest boundaries
We prefer clear product facts over security theater. The items below are not claimed here because they are not established product or certification statements in the repo.
No SOC 2 or ISO 27001 badge claimed on this page
No SAML or enterprise SSO product claimed
No 24/7 dedicated security operations center claimed
No absolute promise that every record is end to end encrypted
Keep reading
These pages expand on the commitments and product surfaces described above.
Full legal wording for collection, use, sharing, and security measures.
Privacy policySession cookies, HTTPS expectations, and no sale of cookie personal information.
Cookie policyAccess, integrations, exports, and backup tools for school tech reviews.
IT department toolsSchool admin messaging, faculty, students, and billing controls.
Admin toolsRead the privacy policy for the authoritative wording, contact support with school specific questions, or request a demo to walk through roles, exports, and payment setup.