Security & trust

Trust should be inspectable, not implied.

This page describes safeguards currently implemented in LeadSharper and the boundaries we intentionally maintain. District-specific legal, procurement, privacy, and contractual requirements are reviewed separately before activation.

Implemented controls onlyDistrict-scoped accessSynthetic public dataNo student account model

Current control posture

What the product does today.

LeadSharper is designed for authorized adult institutional users managing district leadership execution. The controls below are presented as current product behavior, not future intent.

Identity & access

Authenticated workspace access

Protected workspace routes require authentication before district records are loaded.

Trusted district membership

A user must resolve to an active trusted district membership before protected district work is available.

Role-aware permissions

District roles determine whether a user may view, create, change, review, or administer protected workspace records.

District boundaries

District-scoped operating context

Protected records are loaded within the resolved district context rather than falling back to public demo records.

Caller district override rejected

Protected workflows do not trust a caller-supplied district identifier as the source of district access.

Synthetic public examples

Public product examples use synthetic records and are kept separate from protected district workspace data.

Record integrity

Durable evidence review

Formal evidence-review decisions persist with reviewer context, status, notes, and time.

Execution chronology

Ownership, evidence, review decisions, and follow-through remain connected to the leadership record.

Fail-closed access states

Missing or denied protected access does not fall back to customer-like workspace content.

Operational resilience

User-managed encrypted backup

A production logical backup was AES-encrypted, integrity-verified, copied off-device, and a weekly backup workflow was installed for the controlled first-paid scope.

Isolated recovery rehearsal

On August 11, 2026, the verified encrypted production backup was restored into a disposable isolated environment without modifying production.

Support data minimization

Public support instructs users not to submit student records, credentials, authentication codes, private keys, or other sensitive personal information.

Data boundaries

Keep the operating record focused.

Appropriate for LeadSharper

Leadership priorities, cabinet commitments, accountable owners, due dates, implementation evidence descriptions, formal review decisions, and leadership briefs.

Do not submit through public support

Student records, student names or identifiers, passwords, authentication codes, private keys, or other sensitive personal information.

Claims boundary

What this page does not claim.

  • No third-party security certification is represented here unless it has actually been obtained.
  • This page is not a legal compliance determination for any specific district.
  • The tested recovery scope does not represent provider-managed point-in-time recovery, a production-overwrite restore, or a recovery-time SLA or RTO/RPO commitment.
  • District-specific contractual, retention, incident, and procurement commitments are not implied by general product copy.

District review

Need to inspect a specific security or procurement question?

Use the support path for a focused question, or include the topic in a walkthrough request so the current product boundary can be reviewed directly.