Technical Systems, Security & Compliance
Architected specifically for K–12 public education. Explore how Its1Ticket delivers enterprise cloud reliability, strict FERPA data privacy, SAQ A PCI isolation, and financial auditability.
1. Cloud Architecture & Serverless Reliability
Built on serverless edge computing with zero physical server maintenance for school districts.
Its1Ticket operates as a modern Software-as-a-Service (SaaS) platform hosted on Vercel’s globally redundant edge network, managed Supabase PostgreSQL databases, and Cloudflare R2 object storage with 11-nines annual durability.
Zero Local Footprint
No district server hardware, local SQL Server installations, or IIS web hosting required. All releases and patches deploy centrally with zero downtime.
Atomic Row-Locking Concurrency
High-demand rivalry ticket releases execute as atomic database transactions with row-level locking. Overselling is structurally impossible even during massive traffic spikes.
Offline-First Gate & POS Operations
Gate scanning and point-of-sale registers operate fully offline during venue Wi-Fi or cellular failure, validating tickets locally with cryptographic QR signatures and syncing automatically on reconnect.
2. Student Privacy & FERPA Stewardship
Strict K–12 data protection engineered specifically for public school district compliance.
Unlike consumer event platforms that sell attendee data or run advertising, Its1Ticket acts strictly as a "School Official" under FERPA (34 C.F.R. § 99.31). Student data is never sold, marketed, or used to train AI models.
Student Photo Auto-Purge
Attendee photos captured for digital ticket verification are automatically and permanently purged by scheduled sweep within 3 days after event completion (and no later than 7 days post-capture).
Sensitive Field Access Logging
Custom registration fields marked as sensitive (e.g. medical notes) generate visual safety badges and write permanent entries to an append-only audit log whenever viewed by staff.
Zero AI/ML Model Training
Student records, purchase histories, and registration responses are contractually excluded from any third-party or general-purpose LLM / AI training sets.
3. PCI Compliance & Payment Scope Isolation
Keeping school district networks out of PCI scope via Stripe’s Level 1 certified payment elements.
All credit/debit card transactions are processed through Stripe Elements secure iframe overlays. Payment credentials are tokenized directly on Stripe’s PCI DSS Level 1 servers before touching network environments.
SAQ A Scope Isolation
Because cardholder data is tokenized in isolated browser overlays, school district infrastructure qualifies for SAQ A validation, eliminating complex local PCI auditing burden.
Multi-Channel Support
Native support for Apple Pay, Google Pay, Visa, Mastercard, Discover, Amex, Stripe WisePOS smart card readers, and cash/check reconciliation without extra fees.
Automated Sales Tax Calculation
Integrated calculation of state sales tax and county surtaxes (e.g., Florida 6% state + county surtax) mapped automatically by item category and billing jurisdiction.
4. Enterprise Identity & Role-Based Access (RBAC)
Seamless integration with district identity providers and 5-tier role enforcement.
Staff authenticate using their existing district credentials via Single Sign-On (SSO). System permissions are strictly enforced at both application and database Row-Level Security (RLS) layers.
Single Sign-On (OIDC)
Supports federated sign-in via Microsoft Entra ID (Azure AD) and Google Workspace using OpenID Connect protocols. No new staff passwords to manage or store.
5-Tier Role Hierarchy
Granular role-based provisioning: Owner, Admin, Member/Coach, Store Manager (isolated store access with no ticketing access), and Gate & Store Scanner.
Time-Boxed Gate Pairing
Gate scanning devices are paired via secure QR codes or 6-digit PINs without account creation. Access is time-boxed and automatically expires after the event.
5. District Financial Controls & Auditability
Centralized oversight for District Finance and Audit teams with local campus flexibility.
Its1Ticket enforces strict segregation of duties and maintains immutable, append-only logs for all sales, refunds, voids, inventory adjustments, and administrative report views.
Event Publication Approval Workflow
Standard staff event requests start in draft and route automatically to pending_approval until a verified Owner or Admin explicitly reviews and publishes the event.
Append-Only Audit Logging
Every financial transaction, cashier void, inventory adjustment, and report view/export is permanently attributed to a named user with microsecond timestamps.
Hierarchical Budget Code Mapping
Transactions carry district budget codes and general ledger tags for automated export to district ERP systems (such as SAP).
6. Accessibility & Inclusivity (ADA / Section 508)
Ensuring every parent, student, and community member can access event tickets effortlessly.
The fan-facing purchasing and ticket delivery experience is designed following Web Content Accessibility Guidelines (WCAG) 2.1 Level AA and Section 508 accessibility standards.
Keyboard & Seat-Map Alternatives
Complete keyboard operability across checkout, with a dedicated list-based seat selection alternative for reserved seating events that does not rely on canvas graphics.
Screen Reader ARIA Live-Regions
Polite live-region announcements for seat-hold countdown timers, purchase status changes, and shopping cart updates.
High-Contrast & Dual Signaling
All status indicators pair clear text labels or distinct icons alongside color coding so information is never conveyed by color alone.
Need a District Security Questionnaire or FERPA DPA?
View our official FERPA Data Privacy Addendum (DPA) directly, or request assistance with a custom district security questionnaire.