TL;DR:
Private K-12 in Washington (~1,200 students, ~130 staff, no federal funding). A leadership member vibe-coded an internal HRIS/SIS that will hold all staff & student PII/PHI. The build platform is Zite.com. They want to load real student data and wire it to our M365 SSO. I paused it to assess risk. Leadership says security governance kills innovation and they'll "accept the risk." I use AI daily and I'm not a doomsdayer, but this specific use case looks bad to me. Looking for a sanity check and how others have or would handle it.
The setup:
We started drafting an AI acceptable-use policy this spring. Around the same time, a leadership member, a "shadow IT-er", vibe-coded about five internal apps. Four are genuinely useful and cut real costs: inventory tracking, maintenance scheduling, subscription tracking, training trackers. I have zero issue with those and genuinely happy that he's solving those needs and saving money.
The fifth one is the problem. It's a combined HRIS and basic SIS. Every staff member's PII lives in it, and it's built to hold student PII/PHI: allergies, behavioral and discipline records, DOBs, and "more later." It's on test data today, but they're eager to load real students and set up the build provider for M365 SSO. Zite asserts SOC 2 Type II, but seems inherited because they host on AWS, via render.com. They seem much safer than others that have had breaches via Supabase, or stashed secrets in the app itself. But it explicitly doesn't provide privacy protection for apps built by a user: zite.com/privacy "Zite is not responsible for the content of any End User-created App, or for any content or information submitted to any such App."
Where leadership landed last meeting:
Restrictive AI governance stifles innovation. Most personal info is "public anyway." There are no breach reports showing this is actually risky. And in a worst-case scenario, they'll accept the consequences because the savings beat the risk.
Where I am:
I paused it for a couple of weeks to research. We're private with no federal funding, so FERPA doesn't apply. I think COPPA, NIST (as a standard of care), and Washington's RCW 19.255 (breach notification) and RCW 28A.604 (student data) are in play, and I recently found the My Health My Data Act may cover the allergy data. Our cyber insurance renewal and risk assessment are also coming up. I do recall questions about software engineering in there. I love using AI, I use Claude Chat and Code for all sorts of scripting, coding, SOP building, and troubleshooting. I'm not anti-AI in any way.
My questions:
- Gut check: am I overreaching, or are "vet the vendor, classify the data, don't load real student PHI into a vibe-coded, untested app" reasonable baselines?
- As a private, non-FERPA school in Washington, which of these actually bind us? Does RCW 28A.604's "school service provider" language apply to a school that builds its own app, or does it put us outside the statute?
- Cyber insurance: has anyone had a homegrown or undisclosed app holding sensitive data become a problem at renewal or on a claim?
- Culture: when leadership frames security as anti-innovation and says they'll "accept the risk," what actually moved the needle for you?
Thanks. Happy to share back what I learn.