DRIVER VERIFIED · Route 12 · Lincoln ElementaryPICKUP CONFIRMED · Stop 04 · 07:42 AMVEHICLE CHECK PASSED · Bus #218 · Pre-trip completeGEOFENCE ENTERED · Roosevelt Middle · On timePARENT NOTIFIED · Arrival in 3 minAUDIT LOG SEALED · District 47 · 1,284 tripsFACE ID MATCH · Driver #A-091 · Ignition authorizedROUTE OPTIMIZED · –6 min · Traffic reroutedDROP-OFF CONFIRMED · Stop 11 · Signature capturedCOMPLIANCE 100% · Weekly report generatedDRIVER VERIFIED · Route 12 · Lincoln ElementaryPICKUP CONFIRMED · Stop 04 · 07:42 AMVEHICLE CHECK PASSED · Bus #218 · Pre-trip completeGEOFENCE ENTERED · Roosevelt Middle · On timePARENT NOTIFIED · Arrival in 3 minAUDIT LOG SEALED · District 47 · 1,284 tripsFACE ID MATCH · Driver #A-091 · Ignition authorizedROUTE OPTIMIZED · –6 min · Traffic reroutedDROP-OFF CONFIRMED · Stop 11 · Signature capturedCOMPLIANCE 100% · Weekly report generated
Security & Compliance

Every claim on this site has evidence behind it. Ask for it.

Inovantics is built on a security and compliance program designed for the scrutiny that comes with handling student transportation data. SOC 2 Type I readiness in progress. FERPA-aligned. NIST CSF 2.0 mapped. The work is visible — not promised.

This page is maintained by Inovantics to answer common security and compliance questions about the Inovantics platform. It describes app-owned practices and current controls, not independent certification claims.

The Standard

We handle data that matters. We treat it that way.

Student transportation sits at the intersection of children's safety, federal funding, and public accountability. Every system that touches it should be able to show its own work — not point to a badge and ask for trust. This page is how Inovantics shows its work.

Audit Status · Active

SOC 2 Type I readiness — in progress.

What this means

SOC 2 Type I is an independent evaluation of whether the security controls we describe are actually in place — performed by a licensed CPA firm, not self-reported. Type I covers design. Type II — our next milestone — covers operational effectiveness over time.

What this does not mean

Inovantics is not yet SOC 2 certified. We will not use that language until the attestation is complete and the report is in hand.

Inovantics is actively pursuing SOC 2 Type I attestation — the independent audit standard for security, availability, and confidentiality of customer data. The program is being built and operated in partnership with Mostro Cybersecurity & Compliance, with Prescient Security engaged as the independent audit firm.

The audit is in progress. The controls are live. The report follows the evidence.

Regulatory Framework

The regulations that govern student data. Mapped, not just mentioned.

FERPA

Student records are protected under FERPA. Inovantics handles student-adjacent data under FERPA-aligned controls — minimum necessary data collection, no third-party sale or disclosure, district retains ownership of all records.

COPPA

Inovantics' data collection is designed to comply with COPPA's requirements for student-facing systems involving children under 13.

NDAA Section 889

Inovantics hardware components are vetted against the NDAA Section 889 prohibited vendor list and the FCC Covered List. Districts receiving Title I, IDEA, or other federal funding are protected from supply-chain compliance risk. Documentation available on request.

Massachusetts Controls

CORI/SORI handling under MGL c.6 §172. Commercial driver credentialing under MGL c.90 §7B. Special education transport under 603 CMR 28.00. All mapped into the platform's verification layers.

Security Architecture

What the program actually covers.

NIST CSF 2.0

The Inovantics security program is aligned to the NIST Cybersecurity Framework 2.0. Alignment is documented and maintained continuously.

Data Encryption

All data in transit is encrypted. All data at rest is encrypted. Student data is isolated at the application layer.

Access Controls

Role-based access. Multi-factor authentication enforced across all administrative accounts. Privileged access managed through a dedicated PAM platform.

Audit Logging

Every verification event, every data access, every system change is logged with a time-stamped, immutable record.

Continuous Monitoring

Security posture is monitored continuously — not reviewed annually. Threat detection, endpoint protection, and incident response are active at all times in partnership with Mostro Cybersecurity & Compliance.

Biometric Verification & Consent

Driver verification is powerful. The consent framework around it is too.

Inovantics uses facial verification technology to confirm that the driver at the wheel matches the credentialed driver on record. Every driver enrolled in the platform signs a documented biometric data consent agreement before any verification occurs — covering what data is collected, how it is used, how long it is retained, and the driver's rights.

What is not collected: Inovantics does not collect biometric data from students. Facial verification applies to credentialed adult drivers only.

Data Governance

Your data. Your district's data. Protected by design.

Who owns the data

Districts own their data. Operators own their operational data. Inovantics does not claim ownership of customer records.

What we do not do

Student and district data is never sold, never used for advertising, and never shared with third parties outside of documented service agreements. This is a founding commitment — not a policy subject to future revision.

Retention

Data retention schedules are defined per record type and documented in the Data Governance Policy, available on request.

The Partnership

We don't manage security alone — and we shouldn't.

Inovantics' security program is built and operated in ongoing partnership with Mostro Cybersecurity & Compliance. Mostro manages continuous monitoring, policy library maintenance, evidence collection, and the SOC 2 audit engagement with Prescient Security.

A platform trusted with this data should have an adult in the room. Ours does — and their name is on the work.

For Legal Counsel & Procurement

Due diligence shouldn't be a scavenger hunt.

The following documentation is available upon request:

SOC 2 readiness progress report
NIST CSF 2.0 alignment documentation
Data Processing Agreement (DPA) template
Biometric consent agreement (driver-facing)
NDAA Section 889 hardware compliance letters
Massachusetts regulatory controls mapping
Penetration testing summary
Incident response policy
Data retention schedule

We respond within one business day. If your procurement checklist requires a specific answer, contact us directly — we will not make you guess.

The Payoff

What this means for everyone at the table.

For the Superintendent

You signed contracts with confidence. Now you have the evidence to back every one of them.

For Legal Counsel

Every claim on this platform is substantiated. The documentation package exists before you ask for it.

For the IT Director

Encrypted, access-controlled, continuously monitored, and aligned to NIST CSF 2.0. Architecture documentation is in the package.

For the Board

The district chose a partner that holds itself to the same standard it asks of its vendors.

Close

Security you can verify. Not marketing you have to trust.

The work is in progress. The controls are live. The evidence exists.