Public SSO
Support Google and Microsoft personal or organizational identities plus Sign in with Apple, including Apple private email relay.
Strong identity is only the first boundary. Bell2go separates authentication, school authorization, student relationships, active pickup context, and staff verification.
Every sign-in method enters the same mandatory MFA, authorization, audit, and session controls.
Support Google and Microsoft personal or organizational identities plus Sign in with Apple, including Apple private email relay.
Every parent, guardian, or authorized delegate uses a separate verified email and phone number. Phone-based recovery is non-enumerating and revokes old sessions.
Every parent and staff account completes MFA. Provider assurance is validated and Bell2go performs step-up MFA when needed.
Self-registration never grants student access. Roles, guardian and delegate relationships, and school scope come from trusted school approval—not identity claims.
The application backend is built as a Docker image and promoted unchanged through local, pilot, and production environments. Hosted compute connects privately to a managed cloud database.
Location supports active arrival only. The product shows freshness and degrades safely when signals stop.
Student records never belong in marketing forms. Application access requires tenant, role, relationship, and active-session checks.
Plate recognition is optional corroborating evidence. Staff remain responsible for verification; raw imagery follows short retention.
Prediction can recommend timing, lanes, or staffing. It cannot release a student or silently change the approved traffic plan.
CloudFront serves the public website from private S3. Only the demo-request path reaches a small serverless API and an expiring business-lead table. It does not connect to student or dismissal records.