What Red Stet holds, and on whose terms
The posture pages, the retention rules, and the specs a reviewer can check without asking us for anything. This landing exists because the answer to "what is your privacy position" was one page, and the question has always been four.
Policy & posture
Privacy framing, security model, FERPA posture, retention and deletion, and the published specs behind each claim.
11 pages ↓How to use Red Stet
Setting up classes, writing in the editor, marking work, exporting and importing. Step-by-step guides organized by role.
Open /help/ →Methodology
Third-party research behind each signal Red Stet measures. Citations, confidence tiers, and stated limitations.
Open /science/ →Policy & posture
Tap a chip to filter to the pages written for your review.
Start here
The one position everything below follows from.
What this section is. Four posture pages, the retention and disclosure rules that follow from them, and the open specifications a reviewer can verify independently. Nothing here is a summary of a longer document held back for the contract stage — the specs are published and the verifier is open.
Who it's for. District procurement and CFOs sizing the contract. School IT and security reviewers who need the cryptographic model, not the brochure. Teachers deciding what to tell a class. Students and families asking what is held about them. Independent writers with no school in the picture at all.
The position. Red Stet is a writer's personal tool. A school assignment is a use case inside it, not the owner of it. FERPA constrains the submission; the composition fingerprint, the documents, and the recordings outside that assignment stay with the writer.
Privacy
What accumulates when you write here, what is never recorded, and the key model that makes "yours" mean something enforceable rather than promised.
What's recorded, what isn't
The plain-language version of the privacy page — what's captured, what isn't, why provenance alone is useless without the doc, and self-check logging.
The posture pages
The three documents a district review asks for by name.
Security
Encrypted Authorship Verification — the four-layer cryptographic posture, server-derived keys, Sigstore Rekor anchoring, what we see and what we don't.
FERPA posture
FERPA covers the assignment, not the writer. Where the school-official exception applies, where it stops, and what we are explicitly not.
Data retention & deletion
Composition fingerprint as a lifetime asset, the friction-wipe path, FERPA-compliant export, end-of-year cleanup, what gets deleted versus archived.
Check it yourself
The published artifacts behind the claims. None of these require an account, and none of them require us.
The EAV specification
The full protocol for tying writing to its creation history — envelope shape, key derivation, signature and anchor format. Draft redstet-eav:v1.0, published in the open.
The offline verifier
A single static page that checks a .red.md file with no network, no upload, and no account. The signing keys ship inside it.
What "Verified" proves
The integrity checks behind the badge: what they establish, and what they cannot establish without the signature layer.
Disclosure & access
Who can be shown a recording, and how identity is established in the first place.
Sharing a recording with parents or admins
Verifier URLs, what they show without a Red Stet account, and how to interpret one.
School accounts & who administers what
The org model, seats, billing, and which role can see which records.
SSO & identity
Google, Microsoft, Clever, ClassLink. Identity is the first half of the key that decrypts a recording, which is why this page is a policy page as much as a setup page.
Nothing here yet
We haven't published a policy page for this reader yet. Tell us what your review needs: [email protected]
What is not on this page. A signed DPA, a completed vendor security questionnaire, and a current subprocessor list are supplied on request rather than posted, because each one is scoped to the district asking. Email [email protected] and say which you need.
A third-party accessibility conformance report (ACR/VPAT) is not yet complete. ADA Title II applies to public entities on 2027-04-26, and we would rather say that here than have a reviewer discover it in month three.