Every claim on this site has evidence behind it. Ask for it.
Inovantics is built on a security and compliance program designed for the scrutiny that comes with handling student transportation data. SOC 2 Type I readiness in progress. FERPA-aligned. NIST CSF 2.0 mapped. The work is visible — not promised.
This page is maintained by Inovantics to answer common security and compliance questions about the Inovantics platform. It describes app-owned practices and current controls, not independent certification claims.
We handle data that matters. We treat it that way.
Student transportation sits at the intersection of children's safety, federal funding, and public accountability. Every system that touches it should be able to show its own work — not point to a badge and ask for trust. This page is how Inovantics shows its work.
SOC 2 Type I readiness — in progress.
What this means
SOC 2 Type I is an independent evaluation of whether the security controls we describe are actually in place — performed by a licensed CPA firm, not self-reported. Type I covers design. Type II — our next milestone — covers operational effectiveness over time.
What this does not mean
Inovantics is not yet SOC 2 certified. We will not use that language until the attestation is complete and the report is in hand.
Inovantics is actively pursuing SOC 2 Type I attestation — the independent audit standard for security, availability, and confidentiality of customer data. The program is being built and operated in partnership with Mostro Cybersecurity & Compliance, with Prescient Security engaged as the independent audit firm.
The audit is in progress. The controls are live. The report follows the evidence.
The regulations that govern student data. Mapped, not just mentioned.
FERPA
Student records are protected under FERPA. Inovantics handles student-adjacent data under FERPA-aligned controls — minimum necessary data collection, no third-party sale or disclosure, district retains ownership of all records.
COPPA
Inovantics' data collection is designed to comply with COPPA's requirements for student-facing systems involving children under 13.
NDAA Section 889
Inovantics hardware components are vetted against the NDAA Section 889 prohibited vendor list and the FCC Covered List. Districts receiving Title I, IDEA, or other federal funding are protected from supply-chain compliance risk. Documentation available on request.
Massachusetts Controls
CORI/SORI handling under MGL c.6 §172. Commercial driver credentialing under MGL c.90 §7B. Special education transport under 603 CMR 28.00. All mapped into the platform's verification layers.
What the program actually covers.
NIST CSF 2.0
The Inovantics security program is aligned to the NIST Cybersecurity Framework 2.0. Alignment is documented and maintained continuously.
Data Encryption
All data in transit is encrypted. All data at rest is encrypted. Student data is isolated at the application layer.
Access Controls
Role-based access. Multi-factor authentication enforced across all administrative accounts. Privileged access managed through a dedicated PAM platform.
Audit Logging
Every verification event, every data access, every system change is logged with a time-stamped, immutable record.
Continuous Monitoring
Security posture is monitored continuously — not reviewed annually. Threat detection, endpoint protection, and incident response are active at all times in partnership with Mostro Cybersecurity & Compliance.
Driver verification is powerful. The consent framework around it is too.
Inovantics uses facial verification technology to confirm that the driver at the wheel matches the credentialed driver on record. Every driver enrolled in the platform signs a documented biometric data consent agreement before any verification occurs — covering what data is collected, how it is used, how long it is retained, and the driver's rights.
What is not collected: Inovantics does not collect biometric data from students. Facial verification applies to credentialed adult drivers only.
Your data. Your district's data. Protected by design.
Who owns the data
Districts own their data. Operators own their operational data. Inovantics does not claim ownership of customer records.
What we do not do
Student and district data is never sold, never used for advertising, and never shared with third parties outside of documented service agreements. This is a founding commitment — not a policy subject to future revision.
Retention
Data retention schedules are defined per record type and documented in the Data Governance Policy, available on request.
We don't manage security alone — and we shouldn't.
Inovantics' security program is built and operated in ongoing partnership with Mostro Cybersecurity & Compliance. Mostro manages continuous monitoring, policy library maintenance, evidence collection, and the SOC 2 audit engagement with Prescient Security.
A platform trusted with this data should have an adult in the room. Ours does — and their name is on the work.
Due diligence shouldn't be a scavenger hunt.
The following documentation is available upon request:
We respond within one business day. If your procurement checklist requires a specific answer, contact us directly — we will not make you guess.
What this means for everyone at the table.
You signed contracts with confidence. Now you have the evidence to back every one of them.
Every claim on this platform is substantiated. The documentation package exists before you ask for it.
Encrypted, access-controlled, continuously monitored, and aligned to NIST CSF 2.0. Architecture documentation is in the package.
The district chose a partner that holds itself to the same standard it asks of its vendors.
Security you can verify. Not marketing you have to trust.
The work is in progress. The controls are live. The evidence exists.

