Tenant isolation
Customer operations are organization-scoped so one school’s records are not intended to be exposed to another tenant.
This page describes implemented product safeguards. It is not a certification, legal opinion, FERPA determination, SOC report, or guarantee of compliance.
Customer operations are organization-scoped so one school’s records are not intended to be exposed to another tenant.
Administrative and operational roles limit access according to staff responsibilities and supported permissions.
Customer administrators support TOTP 2FA. Platform Owner security additionally supports TOTP and WebAuthn/passkeys.
Administrative and operational activity can be recorded in transaction/audit history for accountability and investigation.
Production tooling includes D1 recovery points, verified SQL backups, automated-backup infrastructure, and restore-drill workflows.
Organization exports include integrity verification, while permanent offboarding requires multiple explicit safeguards before deletion.
Google Workspace and Chrome Enterprise synchronization is designed as read-only for directory/device discovery. CampusOps HQ keeps its own custody and assignment authority instead of silently replacing operational assignments from Google metadata.
Release tooling captures protected counts globally and per organization before and after schema migrations. Existing organization data is expected to remain intact during forward-safe deployment operations.
Schools should evaluate CampusOps HQ under their own policies and legal requirements. Formal privacy, DPA, retention, breach-response, subprocessor, and procurement materials require final business/legal review before general commercial launch.