Verifiable enrollment lottery — a draw anyone can re-run and check
When applications exceed seats, a charter admits by lottery — and the draw itself should be checkable, not just promised. The draw commits a hash of its seed and its rules BEFORE entries close, reveals the seed only at the draw, and anchors the commitment and the result on a SHA-256, hash-chained tamper-evident ledger. From the published seed, rules, and result, a family, a board member, or a journalist re-runs the draw OFFLINE — no phone-home to us, no account, no black box — and confirms three things byte-for-byte: the seed was not swapped after entries closed, the published rules (the tier DEFINITIONS and the seat counts) were not changed, and the result was not reordered. Today the school shares the published record directly (for example as an export) so that check can be run; a public, self-serve endpoint to fetch the record straight from this platform is in active development. Priority tiers (a continuing sibling, an attendance-zone preference, a set-aside) are committed rule DEFINITIONS applied BEFORE any randomness, so changing which tiers exist or how they rank breaks the commitment. Honest scope: cryptographically binding the entrant ROSTER and each entrant’s weight and claimed tier — so the WHO is provably frozen too, not only the seed, the rules, and the ordering — is in active development and is not yet a claim we make. We provide the provable draw mechanism; the school and its board own the roster and the policy. The lottery engine, the commit-reveal draw, and the offline verifier are built and wired. Live money is honest-off — this is enrollment, not a purchase.
Built & wired · offline-verifiable
Opaque tokens only — no student name enters the public draw
The public verifiable record carries OPAQUE entrant ids and the proof — never a name, never a date of birth. The applicant-to-token binding is consent-gated at a single fail-closed chokepoint: an applicant with no recorded directory-information grant, or one under a publication kill-switch, is withheld from the public draw entirely rather than published in redacted form. A family verifies their own token’s position without anyone else’s identity being exposed. The consent gate calls the platform’s one canonical suppression rule — there is no second, copy-pasted copy of the policy to drift. The gate and the opaque-token draw are built and wired. This is the structural difference from a ‘trust our black box’ lottery.
Built & wired · consent fail-closed
Online enrollment & a free student-records tier
Register a student, finalize them onto the roster, and withdraw or transfer — with a consent chokepoint at intake. Seated students flow into a records daily-driver: roster, a gradebook with GPA rollup, printable transcripts and report cards, and immunization-compliance tracking. The student-records tier settles no money — records are the free tier. Honest scope: this is an enrollment-and-records daily-driver that COMPLEMENTS a school’s system of record; it is not a certified, full academic system-of-record, and its roster export is not an IMS-certified integration. The enrollment, gradebook, transcript, and immunization engines are built. No live billing, no subscription.
Built · records tier free
Board governance in the open — policy manual, minutes, named votes
An independent charter board runs its policy manual (draft → active — retired, an immutable version sequence, and a per-requirement staff-acknowledgment ledger), and its meetings (agenda, minutes, motions, and NAMED, on-the-record roll-call votes recorded into the minutes for open-meeting / sunshine-law transparency). A public sunshine-law portal is built to read the adopted record with no login. Honest-off hold: the public-portal minutes-ADOPTION finalizer and the cryptographic e-sign seal are not yet provisioned, so the public portal returns an empty record until that human step is wired — the governance engine and its routes are built and registered; the public-adoption finalizer is honest-off. Nothing here is legal advice.
Built · public-adoption finalizer honest-off
Attendance, ADA & membership — the math, honestly bounded
Attendance is recorded per class meeting, and the engine computes the state-reportable rollup: a present/absent count, an average-daily-attendance ratio (null on a zero denominator — never a fabricated 0/0), and a distinct-student membership headcount. That is the arithmetic behind the numbers a charter’s public role runs on. What is HONEST-OFF: the state / authorizer SUBMISSION channel. The export path stages and validates an extract but submits NOTHING — per-state maps are held for a signed channel and per-state counsel. We do not file ADA to the state, do not calculate per-pupil apportionment or funding, and do not produce a named authorizer report. The attendance and ADA/membership math is built; the submission channel is held.
Built math · state submission honest-off
Special education (IDEA) — deadlines and service minutes
A charter serves every student it seats, special education included. The special-education compliance engine tracks IDEA deadlines and logs service-minute delivery against what a plan requires, surfacing where a due date or a minutes obligation is at risk. It is a deterministic compliance-ops substrate: it tracks and flags; it does not author a plan, render legal advice, or decide a service. The IDEA deadline-and-service-minute engine is built. Student plan data is minor PII — consent-gated, school-owned, and never made public.
Built · compliance-ops