Offensive security in school systems, parent portals, learning platforms and protection of minors' data.
Why now
Children's and adolescents' data is ultra-sensitive under LGPD. Leaks of grades, photos of underage students or family-school communications generate fines, civil suits and reputational crises capable of closing the unit.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Electronic gradebook, grades, attendance, communications.
Unauthorized access to other students' data, family-school messaging.
LMS, online activities, integration with Google Classroom/Microsoft Teams.
CCTV, biometric turnstiles, gate control.
Boleto, direct debit, acquirer integration.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Engagements with school networks and educational institutions.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. Special handling per LGPD article 14 and ECA, with mapping of findings against child/adolescent protection.
Yes. NVR, IP cameras, network segregation, retention and image access.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.