Data Safety LabelsDedham Public Schools concept
Parallel discussion model For vendors: Claim a profile

Vendor data safety workspace

Make vendor risk legible at a glance.

A nutrition-label approach to privacy agreements, cybersecurity evidence, data exposure, and district review. Color is a screening signal, not a final approval decision.

--
approved resources
--
lower-risk signals
--
priority reviews

For vendor representatives

Claim your vendor profile

Find your product, request verification with your business email, and confirm the link we send. A district reviewer then checks your affiliation before you can submit evidence.

Decision spectrumHigher safety
71-100Proceed
46-70Verify
26-45Review
1-25Pause
Lower safety

EdTech Data Safety & Evidence Label

Select a vendor

Choose a product to review its weighted screening signal.

Vendor representative? Select your product in the list to request access.

-- safety
--% evidence
-- confidence
Waiting for selectionReview evidence

The score combines five weighted screening factors.

District review format

Data Safety Facts

Product profile
Deployment contextDedham district use
Data sensitivity--

Select a vendor to see provisional data categories.

District standing--
Privacy agreementVerify record
Security maturity--
Evidence coverage--
Rating confidence--

Unknown controls lower confidence, not maturity.

Framework assurance--
Compliance-- Vendor transparency-- Incident historyDistrict input
Review the current DPA, product scope, evidence dates, and actual district configuration before approval.

Weighted screening model

Vendor risk matrix

The five weighted risk inputs produce a raw safety score. A neutral product starts at 50. Net gains above the old 53-point neutral score are doubled; net shortfalls below it retain their previous point-for-point effect.

Composite vendor safety -- / 100

Unknown security controls are neutral and reduce confidence rather than the Safety Score. Verified negative findings create penalties.

Data Sensitivity rating

Show how harmful the exposed data could be.

Six components measure intrinsic sensitivity and controllable exposure. This is already a risk score, so its contribution is Data Sensitivity Score x 30%. Sensitive-purpose products are not treated as careless when they minimize and tightly manage exposure.

-- data sensitivity -- risk points
High-sensitivity data detectedInventory not reviewed
Intrinsic data sensitivity--Not assessed
Exposure management--Not assessed

Intrinsic sensitivity describes the data itself; exposure management describes how narrowly it is collected, retained, identified, and shared.

Data componentShareRiskWeighted
-- / 100 sensitivity risk -- x 30% = -- risk points
0-19Minimal 20-39Low 40-59Moderate 60-79High 80-100Critical

Unknown inventory fields are shown as unknown and receive a conservative provisional risk value.

Data inventory input

Document the actual district deployment.

Scope and evidence required

Select every category collected or generated, then document identifiability, deployment size, retention, and downstream sharing. Unreviewed vendor input cannot lower the public-evidence baseline.

Data categories collected or generated

What supports this label

Evidence register

Select a vendor to inspect evidence and gaps.

How to read the model

Safety, evidence, and confidence are separate.

30%

Data Sensitivity

Intrinsic data harm separated from controllable identifiability, population, retention, and sharing exposure.

25%

Security Maturity

Underlying control maturity; unknowns are neutral, while verified positives and negatives change the score.

20%

Compliance

District standing plus evidence that legal and framework obligations are addressed.

15%

Vendor Transparency

How clearly the vendor publishes scope, current documents, contacts, and review evidence; external signals are supporting context only.

10%

Incident History

Verified vendor incidents contribute to the score; district-specific impact remains a separate review question.

Vendor participation

Claim this vendor profile

Request access with your business email. Confirm the email link, then wait for a district reviewer to approve your affiliation before adding evidence.

Requester information is retained for identity verification and claim review. Email confirmation alone does not authorize submissions. Already approved? Request an evidence link.