Athena Security supports FERPA compliance for K-12 schools and districts. When a school contracts with Athena, we operate as a “school official” under FERPA (34 CFR 99.31(a)(1)(i)(B)): the school controls its data, we use it only to deliver the security service the school authorized, and we never sell it, share it, or use it for any other purpose.
Athena signs the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement and state-specific agreements including the Texas Student Data Privacy Agreement (TX-NDPA), and complies with state student privacy laws including Texas Education Code Chapter 32, New York Education Law 2-d, California SOPIPA, and Illinois SOPPA.
What student data the system holds
Athena’s weapons detection system does not connect to your student information system, rosters, or student IDs. It has no list of who your students are.
The system generates alert images when the detector flags an object. A student’s name enters the system only when your staff create an incident record and type it in. Your school decides which fields an incident record contains. Incident records typically include the student’s name, a description of the incident, an image of the object, and an image of the person.
How that data is protected
- Encrypted before it leaves the device. Alert images are encrypted on the screening tablet with keys held only on the tablet. They cannot be decrypted in the cloud or in the web interface, by Athena employees or anyone else.
- Never used for AI training. Your alert data is never used to train or improve Athena’s detection models. Detection runs on the screening device at your site, not on our servers.
- Your retention rules. Your school sets retention periods for confirmed-threat records and non-threat records separately, so you can meet state violence-record retention requirements while clearing routine alerts quickly.
- Your delete button. Request deletion of any record at any time through a support ticket; the ticket gives your school an audit trail of every deletion request. Deleted data is purged from backups within 30 days.
- Audited access. Athena staff can only access your data when a support ticket from your school requires it. All access uses two-factor authentication and is logged. Your school can view every audit log.
- Parent access. Your school can grant parents access to audit logs and reports for their student, meeting the FERPA inspection right without routing through Athena.
- Links, not attachments. Alert notifications to staff phones contain a login-protected link, never the image itself. Links expire after a period your school sets, typically 12 hours.
- SOC 2 Type II. Athena is SOC 2 Type II audited and hosted on Linode and AWS in the United States, with encryption in transit and at rest.
- 72-hour breach notification. If a security incident affects your data, we notify your district within 72 hours and post all incidents at status.athena-security.com.
Documents for your privacy officer
- Student Data Privacy Policy
- Parents’ Bill of Rights for Data Privacy and Security
- Subprocessor List
- Security and Data Handling Overview — available under NDA at trust.athena-security.com
- Request our signed SDPC National DPA: [email protected]
Frequently asked questions
Is Athena FERPA certified? There is no FERPA certification; no federal body certifies vendors. Athena’s contracts and practices meet the requirements for a school official under FERPA. We provide a SOC 2 Type II report, the signed SDPC National DPA, and our Student Data Privacy Policy so your district can verify it.
Does Athena hold a list of our students? No. There is no SIS or roster integration. A name enters the system only when your staff type it into an incident record.
Can Athena employees see student data? Only while your school has an open support ticket, on a need-to-know basis, with two-factor authentication, and fully logged. Alert images are encrypted on the tablet with keys only the tablet holds, so nobody at Athena can decrypt them in the cloud application. Your school can see every log entry.
Does Athena use our alerts to improve its AI? No. Customer alert data is never used to train or improve detection models.
Can we keep incident records for five years? Yes. Retention is set by your school, separately for confirmed threats and non-threats. Five years for confirmed threats and 30 days for everything else is a common configuration.
Can we delete data? Yes. Open a support ticket naming the record, or all records for a named student, and we delete it and confirm in writing. Deletion goes through a ticket so your school has an audit trail of every request. Backups purge within 30 days.
How do we handle a parent’s request to see their child’s record? Your school can grant the parent access to that student’s audit logs and reports directly in the platform, or export them and provide them yourself. No ticket to Athena is required.
What happens if there is a breach? We notify your district within 72 hours and post the incident at status.athena-security.com. This meets New York’s 7-day requirement under Education Law 2-d.
What happens to our data if we end the contract? Open a support ticket requesting deletion; we delete all district data within 30 days and confirm in writing. Backups purge within 30 days.
Will Athena sign our data privacy agreement? Yes. We sign the SDPC National DPA and state versions (TX-NDPA, New York 2-d supplement, Illinois, California) as standard. Send any agreement, including a custom district agreement, to [email protected].
Texas districts. We meet Texas Education Code Chapter 32 (no advertising, no profiling, no selling, deletion on request) and SB 820 (district cybersecurity policy flowing down to vendors). We sign the TX-NDPA through the Texas Student Privacy Alliance so other Texas districts can adopt it.
New York districts. We provide the Parents’ Bill of Rights supplement required by Education Law 2-d, align with the NIST Cybersecurity Framework (covered by our SOC 2 program), and commit to breach notice within 72 hours, inside the 7-day requirement.
Does COPPA apply? No. COPPA covers online services that collect data directly from children under 13. Our system collects nothing from students directly; FERPA and state law govern.
Contact [email protected] with any question about student data privacy.
