Student Safety

Our commitment to protecting students

How to read this page

This page says what Zafarios does to protect students and, just as plainly, what it does not do. Safety software is bought on its promises, so the things we do not have are named here rather than left to be discovered later.

Protecting the data

  • In transit: traffic between a device and the servers we run is encrypted with TLS.
  • Separation between schools: one school cannot read another school's records. This is the one security property we have tested exhaustively rather than asserted — every cross-school read we could construct was refused, at both the database and the application boundary.
  • Role-based access: what a person can see follows the role their school gave them. A parent resolves to their own children and is refused another parent's.
  • An audit trail: privileged actions are recorded — who did what, in which school, and when.
  • We do not sell data. There are no advertisers, no trackers sold to third parties, and no secondary use of school data.
  • Not claimed: encryption of the database files at rest, multi-factor authentication, and automatic logout after inactivity. None of the three exists today. If any of them is a requirement for your school, ask us before you commit to anything.

Communication safety

  • Who may message whom is decided by a policy your school sets, not by us. The default is the strict one: students are limited to their own school, and parents cannot message other people's children.
  • A school can require that parent-child messages be visible to staff, or restrict them to school hours. That is a setting, and it is off unless your school turns it on.
  • Not claimed: that every message is read by an administrator. Monitoring is a policy a school chooses, and pretending it is automatic would be a lie in both directions — to the school and to the child.

Safeguarding and incident reporting

There is a safeguarding surface for recording and following up concerns, and its confidentiality is enforced at the database, not merely in the interface: someone outside a case cannot read it, even inside the same school.

  • Staff can record a concern and follow it up.
  • Records are restricted to the people attached to the case.
  • Access is written to the audit trail.

What we do not do

Named plainly, because safety software is bought on what it promises:

  • No live bus or child tracking. There is no GPS, no map, and no location history. Transport is in development and it will not begin with tracking children's locations.
  • No facial recognition and no biometric attendance. Not built, not planned, and never to be attached to attendance.
  • No visitor management.
  • No automatic emergency alerting. There is no push, SMS or email channel behind it.

Regulatory compliance

We do not claim certification or compliance with FERPA, COPPA, GDPR or any other regime, because no assessment has been done and saying otherwise would be the most consequential false claim on this site. What we can tell you is exactly how the software behaves, which data it holds and where it runs, so that your own data-protection assessment has something factual to work from. Ask, and we will answer specifically.

If you run Zafarios on your own servers, you are the controller of that data and none of it passes through us at all.

Reporting Concerns

If you have any safety concerns, please contact us immediately:

Safety Team
Email: safety@lilit.us
For urgent matters, please contact your school administration directly.