Security, privacy, and accountable access
StarPath’s operating controls are designed to protect family information, student records, academic evidence, and authorized school workflows.
Effective July 23, 2026Identity and authorization
Protected routes require verified sign-in. Sign-in establishes identity; separate server-side membership and role checks determine whether that identity may enter the StarPath workspace and which records it may access.
Least-privilege roles
Administrative, academic, advising, admissions, guardian, and student roles receive different capabilities. Guardian and student accounts are restricted to explicitly assigned student records.
Data protection
Structured records are stored in the site’s managed database and uploaded evidence is stored separately in managed object storage. File uploads and downloads enforce identity and student-access checks.
Accountable actions
Material operations—including invitations, enrollment changes, evidence activity, mastery decisions, interventions, and admissions updates—create timestamped audit entries attributed to the signed-in user.
Operational safeguards
The application validates input, limits upload size, prevents accidental duplicate inquiries, restricts browser caching for protected responses, and returns minimal public health information.
Compliance posture
Technical controls support responsible education operations, but compliance also depends on approved policies, staff training, contracts, retention schedules, incident procedures, and legal review appropriate to StarPath’s jurisdictions.

