Every EdTech contract you sign is also a data-privacy and cybersecurity decision, even when procurement never frames it that way. A new reading app, a scheduling tool, a parent-communication platform: each one touches student data, connects to your network, and becomes something your school is accountable for. Most of the time nobody outside IT is asked to weigh in until the invoice is already on someone’s desk.
That’s backwards. Here’s how we’d think about it.
“It’s Just Software” Is a Myth
A single-sign-on integration, a rostering sync, a new vendor with API access to your student information system: these aren’t small technical details. They’re new doors into your network, and every door needs a lock. In K-12, where budgets are tight and staff often wear five hats, EdTech vetting tends to get compressed into “does it do what we need” and “can we afford it.” Security and data governance get asked about after the contract, if at all.
Five Questions Before You Sign
- Where does student data live, and who owns it? Get specifics: server location, retention period, and whether the vendor can use the data for anything beyond delivering the service.
- What’s the vendor’s incident response commitment? Ask for their breach notification timeline in writing, not a verbal assurance. If they can’t answer quickly, that’s your answer.
- How does this tool connect to what you already run? Every integration is a new access point. Map it before you approve it, not after something breaks.
- What happens to our data if we cancel? Deletion terms matter as much as onboarding terms. Get an exit clause, not just a start date.
- Has this vendor had a breach, and how did they handle it? A past incident isn’t automatically disqualifying. How transparently they handled it tells you more than the incident itself.
Bring IT to the Table Before the Demo, Not After the Invoice
The schools that manage this well share one habit: IT or their MSP partner is in the room during vendor evaluation, not looped in after the purchase order is signed. That single change, moving security review earlier in the timeline, prevents most of the painful surprises we see later.
A Simple Rule for Charter and Independent Schools
You likely don’t have a dedicated procurement security team, and you don’t need one to do this well. You need a short, repeatable checklist and someone with the authority to say “not yet” until the questions above are answered. That’s a policy decision, not a technical one, which is exactly why it belongs with school leadership, not buried in an IT ticket queue.
This is the same thinking behind everything we build at Inspiroz. We keep schools safe by treating every technology decision as a leadership decision, not just a purchasing one. If you want a second set of eyes on a vendor before you sign, or want to build this checklist into your own procurement process, that’s a conversation we’re always happy to have.
Want more on this? Check out The Connected School Podcast, where we dig into the IT, cybersecurity, and AI decisions shaping K-12 schools today.





