Trust & Security
Read this before the meeting, not after.
Every label below tells you exactly what stage a control is at — already true of this site today, a commitment we make before any pilot goes live with real school data, or a design principle the production platform is being built around. Nothing here claims a certification Kinnovar doesn't hold.
Trust and security principles
Data minimization
Design principleKinnovar is being built to collect only what a transport handoff and a parent notice actually require — not a broader profile of a child or family. This marketing site collects only business contact information that a visitor chooses to submit through its inquiry form. The form explicitly prohibits student, child, guardian, health, and location information.
Tenant isolation
Design principleEach school's users and data are isolated from every other school's. Country, region, and municipality are reporting and onboarding layers only — never a path to another school's data. This is an architecture requirement, not a configuration option someone could disable.
Role-based access, least privilege
Design principleSchools, transport staff, and families each see what's relevant to their role, and nothing more. Staff access is scoped to what a role needs to do its job.
Multi-factor authentication
Pilot commitmentMFA for staff accounts is a pilot-launch standard — required before any pilot school's staff get production access, not an optional add-on considered later.
Encryption in transit and at rest
Pilot commitmentProduction data is designed to be encrypted both in transit and at rest. This applies once the production platform exists — there is currently no production platform or database, only this marketing site.
Auditability
Design principleEvery recorded event — a boarding, a notice, an exception, an action taken — stays reviewable after the fact, for the school and for the family. This is the same auditable-history idea shown on the homepage, applied as a system requirement.
Backups and tested restore
Pilot commitmentTested backup and restore procedures — not just backups that exist but restores that have actually been verified to work — are a requirement before any pilot goes live with real school data.
Retention and deletion
Pilot commitmentClear rules for how long data is kept and how it's deleted are defined before pilot data collection begins, not written after the fact.
Controlled support access
Design principleIf Kinnovar staff ever need to access a school's data to provide support, that access is logged, scoped, and limited to what the support case requires.
Incident response
Pilot commitmentA written incident response playbook — who's notified, how, and how fast — is a requirement before pilot launch, not something assembled after something goes wrong.
Vendor controls
True todayEvery vendor or tool that could touch submitted information is recorded in an internal vendor register — including purpose, permitted data, owner, and status — before it is used. Netlify processes website-form submissions, and a founder-managed email provider receives the notification.
Location-data discipline
True todayA boarding record or a location update is a timestamped fact — never described as proof that a child is "safe," "present," or "delivered." That distinction is enforced in this site's own copy today, and it's a hard requirement for the production product, not a marketing nuance.
Responsible use of AI
Design principleKinnovar will not use AI to profile children or to make eligibility, behavior, or risk decisions about them — not with human review, not without it. If AI is ever used in the product at all, it stays limited to operational support, and customer-facing messages are never sent without appropriate human review.
Accessibility
True todayWCAG 2.2 AA is the target for this site, built in during construction rather than bolted on afterward — plain language, visible focus states, and status that's never conveyed by color alone. Formal conformance isn't claimed publicly yet; this is an engineering target being actively worked toward.
What we don't claim
Kinnovar does not currently hold SOC 2, ISO 27001, FERPA, COPPA, or GDPR certifications or formal attestations. We'll say so plainly and specifically if and when that changes — not imply it earlier than it's true.
Questions before a pilot conversation?
A principal, IT lead, or privacy reviewer is welcome to ask us anything on this page directly.
Request a Pilot