FiscalTrack
Security & privacy

What happens to the money, the ledger and the student's name.

Written plainly for the people responsible for all three. Specific controls are more useful than a wall of security adjectives.

Core controls

Designed so important promises are enforced by the product.

The ledger, access model and payment flow are structured to make silent changes and casual access harder.

The ledger seals itself

Each entry carries a code computed from its contents and the entry before it. Change an old record and the sequence breaks.

Entries are voided with a reason, never deleted.

FiscalTrack never holds your money

Card payments settle into your own account through your own processor. Funds do not pass through a FiscalTrack balance.

Student data stays minimal

The roster holds what is needed to charge a fee and nothing more. District fee totals do not expose a student's name or individual balance.

Student names stay out of the audit log.

Staff cannot browse your ledger

The operator console has no route that returns a transaction, receipt, requisition or count, and no impersonation.

If support genuinely needs records, FiscalTrack asks you for them.

Two-step verification

Available to everyone and can be required for people who can move money. Authenticator apps are the stronger option; emailed codes are labeled as weaker.

Accessible by default

Both themes meet WCAG 2.1 AA contrast. Keyboard focus, reduced motion and Windows high contrast are supported.

Access boundary

What FiscalTrack can see—and what it cannot.

A useful security review should make the boundary obvious.

FiscalTrack staff can see
  • Organization-level counts
  • Plan and billing state
  • Information you deliberately send for support
FiscalTrack staff cannot browse
  • Ledger transactions
  • Receipts and requisitions
  • Cash counts
  • Your account through impersonation
District oversight

Access is granted, and the access itself becomes part of the record.

For custodial funds, district access is deliberate, carries a stated reason and is shown to the school. For governmental funds, line-item access is available because the district controls the money.

Two fund contexts

  • Governmental funds: district line-item access needs no special justification.
  • Custodial funds: access is granted deliberately and every access is recorded.
  • Schools can see who has looked at custodial fund records.
Your data

It is yours, and you can take it.

FiscalTrack's position on sale, export, closure and hosting is deliberately simple.

Do you sell data, or train models on it?

No. Not to anyone, not in aggregate, not anonymized. It is a school's financial records and a roster of children's names.

What can we export?

Everything, as CSV: the ledger, funds, counts, people and the full audit log. It is available at any time, not only on the way out.

What happens if we close the account?

Closure runs on a waiting period rather than an instant delete button. Sign-in stops, the export is offered and nothing is destroyed until the period expires. Closure can be cancelled until then.

School financial records can carry statutory retention requirements, so immediate erasure is intentionally not the default.

Can you sign a data privacy agreement?

Yes. Districts should ask for one, and FiscalTrack expects it.

Where is it hosted?

In the United States. Backups are encrypted, and the key that seals the ledger is stored separately from the database it protects.

Bring your hardest question.

If your district has a security review, procurement checklist or records schedule FiscalTrack needs to meet, send it over.