What data is collected and stored when a visitor ID is scanned into the Raptor system?
What is the Raptor’s data retention policy?
How is the data used? To what purposes am I authorizing its use?
Is the data shared with any third parties? If so, which ones and which data?
How is the data protected?
How is the datacenter physically secured? Do they collocate? If so, is the cage physically secured and how?
Is the data encrypted on disk?
How are all communications to the system and within components of the system secured?
Who has access to the data? What access do Raptor employees have to the data?
What access do district/school employees have to the data?
Have all Raptor employees with access to private data been screened, and have they signed proper non-disclosure agreements (not just protecting Raptor's intellectual property, but with regard to the data collected and stored about individuals)?
What are the password requirements for internal and external users (length, complexity, recycle, etc.)?
Can a user review the data collected about them to ensure it is accurate?
Whether an entrant can review their data would be a policy decision on the part of the district/school and not a decision by Raptor.
Is the software open source or closed source?
Does Raptor have adequate quality assurance practices to reduce the likelihood of data leaking bugs?
What is Raptor’s disclosure policy with regards to discovered vulnerabilities and possible or actual leaks of data?