Limited beta · For universities, colleges, and K-12 districts

Share classroom recordings without sharing student identities.

COPAL FERPA Agent turns a classroom, lecture, or meeting recording into a FERPA-safe copy through a conversation. Upload it, review who appears and what was said, choose who to protect, and export. If anything slips through, select it on the rendered video and mask it on top. Every consequential step is confirmed by a person and written to an audit trail.

Faces blurred and tracked as people move Spoken names, IDs, and contact details silenced Each speaker's voice anonymized individually On-screen names and text covered Touch up any frame after rendering, no video editor Every export attributed and logged
sec-03-lecture-2026-09-14.mp4rendering preview · 84%timecode 00:12:41 / 00:30:12immutable master
FACE 1
Face 1
FACE 2
Face 2
FACE 3 · KEEP
Face 3
FACE 4
Face 4
FACE 5
Face 5
FACE 6
Face 6
FACE 7
Face 7
FACE 8
Face 8
FACE 9
Face 9
FACE 10
Face 10
FACE 11
Face 11
FACE 12
Face 12 00:12:41
00:12:41 / 00:30:1211 faces blurred6 spans silenced11 voices anonymized1 face kept
00:00
30:12
Faces detected · 12 select to bluraudit entry #A-2291
Face 1blur
Face 2blur
Face 3keep
Face 4blur
Face 5blur
Face 6blur
Face 7blur
Face 8blur
Face 9blur
Face 10blur
Face 11blur
Face 12blur
11 faces blurred · 11 voices anonymized · 6 spans silenced (4 names, 2 student IDs) · 12 on-screen names covered1 face remains identifiable: Face 3
The problem

Recordings are useful. Sharing them is where it gets hard.

Teaching observation, instructional coaching, lecture capture, research under IRB, accreditation evidence, parent and records requests. All of these need a copy of a recording that does not disclose who the students are. A student's face and voice are personally identifiable, and once a recording leaves the course it is an education record someone has to answer for.

Today the choices are poor. Frame-by-frame editing takes hours per recording. Generic blur tools lose a face the moment a student turns or stands up, and do nothing about the names, student IDs, and email addresses that get said out loud or shown on a slide. So recordings either sit unused, or get shared with a risk nobody has measured.

OriginalUnredacted education record
Amara N.Prof. Okafor00:12:41
TRANSCRIPT · 00:12:41…thanks, Amara. Can you read your student ID, 4471-0928, for the record? Then we'll hear from Diego.
7 faces visiblenames on screennames + ID spoken
Protected copyFERPA-safe de-identified copy
FACE 1
FACE 2 · KEEP
FACE 3
FACE 4
FACE 5
FACE 6
FACE 7
Face 1Face 200:12:41
TRANSCRIPT · 00:12:41…thanks, silenced 0.5s. Can you read your student ID, silenced 1.4s, for the record? Then we'll hear from silenced 0.4s.
6 faces blurred, trackedinstructor keptlabels replaced3 spans silenced6 voices altered
How it works

Four steps, one screen.

You do not configure a redaction pipeline or open a video editor. You upload, look at who appears and what was said, choose who to protect, and confirm. The system does the rest.

01 — UPLOAD

Drop in a recording, or several.

The original is transcoded once into an immutable master and never altered. Long recordings ingest in the background while you do something else.

02 — REVIEW

See who appears and what was said.

Live face overlays on the video, a gallery of every detected person with a face thumbnail and voice sample, and a transcript with names, student IDs, emails, and phone numbers highlighted. Text on slides and whiteboards is picked up too.

03 — CHOOSE

Pick who to protect, and say why.

Tap the people to anonymize, tune the blur, choose voice anonymization, and give the reason the recording is being shared. A short preview renders in seconds so you can compare it with the original before committing.

04 — EXPORT

Confirm, render, download.

You confirm a summary of exactly what will happen, acknowledge who stays identifiable, and your typed reason is recorded verbatim. If something was missed after the render, select it on the video and add a blur or mask on top; only that segment re-renders.

Masks move with the room · detection runs on every frame, so the mask follows a student who turns, stands, or walks out, and lets go when they are gonelecture-hall-2026-09-21 · 25 faces · 00:41:07
FACE 1
FACE 2
FACE 3
FACE 4
FACE 5
INSTRUCTOR · KEEP
00:41:07
24 students masked, 1 instructor keptFaces turned toward a neighbour, half hidden behind a laptop, or three rows back are tracked as the same person from the moment they enter the frame until they leave it.
What it does

Built around the FERPA moment, not the video editor.

Every feature exists because something goes wrong at the moment a recording leaves the course.

Moving face blur

Detection runs on every frame, so the mask follows people as they move, turn, leave, and come back, and releases when they are gone. A feathered mask and adjustable strength keep the rest of the room watchable.

Spoken PII, silenced

The recording is transcribed with word-level timing and scanned for names (including spelled-out and "call me" forms), student IDs, emails, phones, and addresses. You see every span and exactly how many will be silenced before you export. You can add your own roster of names to look for.

Every voice anonymized, individually

Beyond silencing what was said, each speaker's voice can be altered on its own, so a discussion still sounds like different people talking but none of them sounds like themselves. No student's voice is ever cloned.

On-screen text, covered

Names and IDs that appear on slides, rosters, or whiteboards are found by OCR and covered with opaque boxes, while slide titles and content stay visible.

Touch up after rendering, no video editor

If a name on a whiteboard or a face in a reflection slipped through, select it on the rendered video and add a blur or an opaque mask on top, for the frames you choose. Only that segment re-renders, and the touch-up is logged like any other action.

A human confirms every export

Nothing renders without an operator naming the targets, reading the consequences summary, acknowledging who would remain identifiable, and typing a reason. The agent cannot skip this step.

Two-layer audit trail

Every action is logged before it is forwarded, and again in an append-only database log that cannot be edited in place. Actions are attributed to the signed-in account. An auditor role gives compliance staff read-only access to all of it.

Leak check after render

Every preview and full render is re-scanned for faces that slipped through, and any output can be re-validated on demand.

No generation loss

Exports composite the immutable master with per-person patches. Untouched segments are copied verbatim and re-exports reuse work already done, so a recording edited five times looks like one edited once.

Processing inside a secure boundary

Storage, detection, transcription, rendering, and the audit log all run inside your institution's workspace, on dedicated infrastructure during the beta. Media leaves only as an export a signed-in user downloads. Face detection can optionally run in your browser before upload.

Gallery recordings, seat by seat

Zoom and Meet gallery recordings are handled as a grid of seats, so each participant is tracked, blurred, and voice-anonymized as their own person even when tiles shuffle.

Roles, scoping, and API access

Operators work with recordings, admins manage users and the queue, auditors read. Everything is scoped to your institution. The same nine operations behind the chat are available over MCP to Claude Desktop, Cursor, or your own agents, through the identical validation and audit path.

Where the work happens

Data and processing stay inside a secure boundary.

A recording enters your institution's workspace once and stays there. Storage, detection, transcription, rendering, and the audit log all run inside that boundary, and media leaves only as an export downloaded by a signed-in user.

Who it is for

Made for the people who actually handle the recordings.

Teaching and learning centers

Share observation and coaching recordings across departments without a consent chase for every student in the room.

Lecture capture and instructional design

Reuse recorded lectures for future cohorts, open courseware, or training material.

Research offices and IRBs

Produce de-identified video for studies and secondary analysis, with the audit record to show for it.

K-12 districts

Support professional development, teacher evaluation, and records requests without exposing minors.

Compliance and privacy officers

Get a per-export record of who did what, to which recording, and why.

Ed-tech and research platforms

Integrate the pipeline into your own tools over MCP and inherit the confirmation and audit model.

The limited beta

We are opening a small number of seats.

COPAL FERPA Agent is in a limited beta. We review every request by hand and admit institutions in small cohorts so we can work closely with each one.

What you get

  • A hosted workspace for your institution on dedicated infrastructure, with accounts for your operators, admins, and auditors.
  • The full pipeline: face blur, spoken-PII silencing, on-screen text covering, preview, export, and audit.
  • A direct line to the team building it, and a real say in what gets built next.
  • Beta access is free of charge.

What we ask

  • Recordings you are authorized to upload. Real classroom material, or realistic stand-ins, is what makes the feedback useful.
  • A short feedback conversation every few weeks.
  • Patience with rough edges. This is a beta, and we will tell you plainly what is and is not ready.
Request access

Request beta access

Tell us who you are and what you would use it for. We review each request personally and email you when a workspace is ready.

I am requesting as

Requests are reviewed by a person, so it may take a few days. We use your email only to reply about the beta.

FAQ

Questions we get asked.

Does it replace faces with different faces?

No. In the current release faces are blurred, not swapped. Blur is deterministic and easy to audit. Photorealistic replacement is on the roadmap as a separate option once we are satisfied it can be verified.

What happens to voices?

Two things, and you choose either or both. Spans of speech that contain personal information are silenced. And each speaker's voice can be anonymized individually, so different people still sound like different people but nobody sounds like themselves. We never clone a student's voice.

What if the render missed something?

Every render is re-scanned for faces that slipped through. If you spot something the scan did not, such as a name on a whiteboard, select it on the rendered video and add a blur or mask on top for the frames you choose. Only that segment is re-rendered, and the touch-up is written to the audit log like every other action. You never need a separate video editor.

Where does the processing happen?

Inside your institution's workspace. Upload, storage, detection, transcription, rendering, preview, export, and the audit log all run within that boundary, on dedicated infrastructure we operate during the beta. Media leaves only as an export downloaded by a signed-in user, and that download is logged like everything else.

Can it run in our own environment?

That is the intent. The product is built to run on-premises or in your own cloud account, and that is how we plan to deploy it for institutions after the beta. During the beta it runs on dedicated servers we operate, with one isolated workspace per institution.

Which recordings work?

Common video formats up to 8 GB per file. Classroom cameras, lecture capture, and Zoom or Meet gallery recordings.

How long does processing take?

It depends on length and content. Ingest runs in the background and you are shown progress for the audio and video lanes separately. Previews of a chosen segment render in seconds; a full render is proportional to the length of the recording.

Is this a substitute for our FERPA review?

No. It produces de-identified copies and an audit record of how they were made. Whether a given disclosure is permitted remains your institution's decision, and nothing here is legal advice.

Can we integrate it with our own tools?

Yes. The nine operations behind the chat are available over MCP (stdio and HTTP), gated by a key, and pass through the same validation and audit path.

What does it cost?

Nothing during the beta. We will share pricing with beta participants before general availability.