Trust Center

Procurement questions, answered before you have to ask them.

Districts cannot approve a partner that is vague about student information. This page describes how Future1 handles data, who can see what, and what your district keeps.

This page is maintained by Future1 Community to answer common security and privacy questions about our platform and services. It describes our current practices and enabled controls. It is not an independent audit, a certification, or a legal guarantee.

Data ownership

Your records are yours.

The most important commitment on this page, so it goes first.

District records stay district records

Employer contacts, commitments, placements, follow-up history, and reports belong to the district. Future1 is the operator of the system, not the owner of the content.

Exit means export

If an engagement ends, your records are exported to you. We build a system you keep rather than a dependency you rent.

Student records live with the school

Future1 does not become a system of record for academic data. Grades, transcripts, discipline, and eligibility remain in district systems.

We do not sell information

Partner and district information is never sold, rented, or used to build a marketing list for anyone else.

Access

Who can see what

Access levels by role
RoleCan seeCannot see
District and school staffTheir district's employers, placements, follow-up, and reportsAny other district's records
Employer partnersTheir own placements, commitments, staff, and feedbackStudent academic records, other employers, other districts' data
Future1 staffOnly the accounts they are assigned to operateAccounts outside their assignment
Students and familiesTheir own participation and opportunitiesAny other participant's information

Access is enforced per account at the database layer, not only in the interface, and every workspace is scoped to the organization it belongs to.

Platform controls

What is in place today

Authenticated access only

Every workspace requires an account. There are no shared logins and no anonymous access to district or employer data.

  • Per-account sign-in
  • Role-scoped permissions
  • Access removed when a person leaves

Encryption in transit and at rest

Traffic is served over HTTPS and stored data is encrypted at rest by the managed cloud infrastructure the platform runs on.

Row-level access enforcement

Data access rules are applied in the database, so a request cannot reach another organization's rows even if the interface is bypassed.

Reporting with small-count suppression

Aggregate reports suppress small counts so individuals cannot be identified from a summary figure.

Data minimization by default

Each role receives the minimum information its job requires. Employer-facing surfaces are built around that constraint.

Managed cloud hosting

The platform runs on managed cloud infrastructure with maintained backups; we do not operate our own servers.

Shared responsibility

Who is responsible for what

Future1

  • Operating the platform and its access controls
  • Handling records under the terms of the engagement
  • Notifying the district of a security incident affecting its data
  • Training our staff on data handling

The district

  • Remaining the record owner and legal steward of student data
  • Deciding which staff receive access and at what level
  • Obtaining any consent its policy or state law requires
  • Removing access when staff change roles

Employer partners

  • Providing a safe, supervised worksite
  • Using student information only to supervise the placement
  • Not retaining or redistributing student information
  • Reporting concerns to their Future1 contact

Accessibility

Our accessibility commitment

We build toward WCAG 2.1 AA: keyboard-operable interfaces, visible focus, semantic structure, text alternatives, and sufficient contrast. Where we fall short we want to hear about it and fix it. Read the accessibility statement.

Contact

Security, privacy, and data requests

Report a security concern

Send details of a suspected vulnerability or incident and we will acknowledge it. Good-faith reporting is welcome.

Security policy

Privacy and data questions

Questions about how information is handled, or a request relating to your own account information.

Questions

The questions districts actually ask

Straight answers, including where the honest answer is 'it depends'.

Need this in a procurement packet?

Tell us what your review process requires and we will provide the scope and data-handling documentation in the format your office needs.