Higher education

Education records are wider than you think.

Advising notes, admissions essays, recommendation letters, disciplinary files. Itzal detects FERPA-relevant data in the composer, on institution-owned devices, before submission — without student data reaching our servers.

INSTITUTION-OWNED STUDENT-OWNED OUT OF SCOPE
Staff and faculty devices. Student devices are out of scope by design.
Built for Universities Colleges School districts Research institutes

What’s specific here

Four things that make campuses different.

Student records reach AI tools through entirely ordinary academic work: advising notes summarised, admissions essays evaluated, recommendation letters drafted, disciplinary documentation rewritten, grade appeals answered.

Education records are broad

FERPA covers essentially anything directly related to a student and maintained by the institution — grades, transcripts, discipline, advising notes, accommodation records, financial aid. A far wider surface than “PII” in the ordinary sense.

Context makes the identifier

A student ID number alone is one thing. The same number next to a grade or a disciplinary note is an education record. Detection is weighted by academic context terms, editable per institution.

Decentralisation is the real problem

Universities are federations of departments with their own devices, their own browsers and their own opinions about central IT. A control assuming uniform managed endpoints will have gaps — which should be measured and published rather than assumed away.

Special categories stack

Health records at the campus clinic, research data under an IRB protocol, and payment data in the bursar’s office each carry their own obligations on top of FERPA, and each benefits from its own custom rules.

Scope

Staff devices. Not student ones.

Itzal is deployed on institution-owned faculty and staff devices. Student-owned devices are out of scope by design, and that boundary belongs in your notice, stated plainly.

Faculty privacy is a live concern on any campus, and the architecture matters here more than the policy language: administrators see a data type, a count, a confidence, a masked snippet and a destination. Nobody can read what a faculty member wrote, because the system never received it.

How that works

Before deployment

  • Notice requirements come first, and at many institutions so does faculty senate or union consultation.
  • Publishing what is not collected does more for adoption in an academic environment than any amount of policy language.
  • Start with one administrative unit, in log-only mode, and measure against real academic language.
  • Coverage is reported per device, so a department that never enrolled is visible rather than assumed compliant.

Straight answers

Does FERPA prohibit using AI tools with student data?

FERPA restricts disclosure of personally identifiable information from education records without consent, subject to exceptions such as the school official exception. Whether a given AI vendor qualifies depends on the contract and on your institution's determination.

Does Itzal monitor students?

No. It is deployed on institution-owned staff and faculty devices. Student-owned devices are out of scope by design.

What about research data?

Human subjects data under an IRB protocol is typically higher-sensitivity than FERPA records, and benefits from custom rules — protocol numbers, participant ID formats — rather than generic detection alone.

Not legal advice. Whether a particular vendor qualifies under the school official exception is your institution’s determination, made with counsel.

Start with one administrative unit.

Bring the academic language your staff actually write, and we will show you what fires and what does not.