District records stay district records
Employer contacts, commitments, placements, follow-up history, and reports belong to the district. Future1 is the operator of the system, not the owner of the content.
Trust Center
Districts cannot approve a partner that is vague about student information. This page describes how Future1 handles data, who can see what, and what your district keeps.
This page is maintained by Future1 Community to answer common security and privacy questions about our platform and services. It describes our current practices and enabled controls. It is not an independent audit, a certification, or a legal guarantee.
Data ownership
The most important commitment on this page, so it goes first.
Employer contacts, commitments, placements, follow-up history, and reports belong to the district. Future1 is the operator of the system, not the owner of the content.
If an engagement ends, your records are exported to you. We build a system you keep rather than a dependency you rent.
Future1 does not become a system of record for academic data. Grades, transcripts, discipline, and eligibility remain in district systems.
Partner and district information is never sold, rented, or used to build a marketing list for anyone else.
Access
| Role | Can see | Cannot see |
|---|---|---|
| District and school staff | Their district's employers, placements, follow-up, and reports | Any other district's records |
| Employer partners | Their own placements, commitments, staff, and feedback | Student academic records, other employers, other districts' data |
| Future1 staff | Only the accounts they are assigned to operate | Accounts outside their assignment |
| Students and families | Their own participation and opportunities | Any other participant's information |
Access is enforced per account at the database layer, not only in the interface, and every workspace is scoped to the organization it belongs to.
Platform controls
Every workspace requires an account. There are no shared logins and no anonymous access to district or employer data.
Traffic is served over HTTPS and stored data is encrypted at rest by the managed cloud infrastructure the platform runs on.
Data access rules are applied in the database, so a request cannot reach another organization's rows even if the interface is bypassed.
Aggregate reports suppress small counts so individuals cannot be identified from a summary figure.
Each role receives the minimum information its job requires. Employer-facing surfaces are built around that constraint.
The platform runs on managed cloud infrastructure with maintained backups; we do not operate our own servers.
Shared responsibility
Accessibility
We build toward WCAG 2.1 AA: keyboard-operable interfaces, visible focus, semantic structure, text alternatives, and sufficient contrast. Where we fall short we want to hear about it and fix it. Read the accessibility statement.
Contact
Send details of a suspected vulnerability or incident and we will acknowledge it. Good-faith reporting is welcome.
Security policyQuestions about how information is handled, or a request relating to your own account information.
Questions
Straight answers, including where the honest answer is 'it depends'.
Tell us what your review process requires and we will provide the scope and data-handling documentation in the format your office needs.