Security

Clear permissions. Explicit handoffs.

Security controls built around student data and the real responsibilities of a school dismissal team.

Authorization on the server

Every school API validates the signed-in account, active school membership, and permitted role. Student access is constrained to the authorized school and relationship or classroom. A school identifier sent by a browser is never accepted as authorization.

Staff verification is required

The server enforces a strict state machine. A teacher can send a student only after a staff member verifies the pickup person. Authorization and active restrictions are checked again when actions are processed. GPS and pickup passes cannot create a release request.

Protecting accounts

Passwordless sign-in uses short-lived email codes, limited verification attempts, and database-backed rate limits. Sessions use HttpOnly cookies, HTTPS in production, same-site protection, rotation, and request-level CSRF checks. Users can enroll passkeys or an authenticator; schools may require verified use before staff access school records.

Temporary pickup passes

Pickup passes are cryptographically signed, expire after 60 seconds, and are redeemed once on the server. They contain opaque identifiers rather than student names. A successful scan identifies the account; it does not change dismissal state.

Reliable records and reconnection

State changes, event records, and audit entries commit in one database transaction. Version checks and idempotency keys defend against duplicate and stale commands. Durable event sequence numbers allow clients to recover after a connection drops. Audit and pickup-event tables reject normal updates and deletion.

Practical safeguards

Validated inputs, parameterized database access, restricted origins, secure headers, production bot checks, and limited database connection pools support the application. Operational logs avoid student names, email codes, raw locations, and session tokens. Logo uploads are limited to validated raster image formats.

Reporting a concern

Contact the school service operator through the contact form with a general description and a way to reach you. Do not include student records, credentials, or exploit payloads in a public message. DismissLane does not claim security certifications or independent audits that have not been obtained.

Contact DismissLane