Architecture
The System
Pioneer is the whole local security platform — video, badge access, network defense, monitoring, and Care — not a camera-only add-on. Everything below runs in your building. Pioneer designs and configures; a certified partner installs physical cameras, cable, readers, and strikes.
Why local matters
Cloud school platforms get breached constantly. 82% of K–12 schools experienced cyber threats in 2024; ransomware recovery averages about $2.28M; PowerSchool-class incidents have exposed 60M+ student records. SSNs, health files, and IEPs do not belong on a forever-rented cloud edge.
Cloud camera dashboards add another risk: if an attacker reaches the feed, they can see where people are in the building in real time — and on a college campus that attacker may be a student, not a distant nation-state. Pioneer’s stack below is local-first — video on a segmented VLAN in your building, not a public cloud login. Fewer remote doors into the surveillance path.
Mac Mini
The local brain. Hosts the application stack (via containers) for video, access automation, DNS filtering, VPN endpoints, monitoring, and backups. Quiet, efficient, and designed to live in a network closet — not a cloud region.
Protectli + OPNsense
A dedicated appliance runs OPNsense as the traffic authority between the internet and your segmented campus network. Policies decide which VLANs can talk, what leaves the building, and how remote access is gated.
Frigate NVR
On-premises network video recording with AI-assisted detection. Streams stay local. No per-camera cloud subscription. Events and retention live on hardware you control.
Listed door hardware + local automation
Door schedules and badge events run locally. A certified install partner mounts readers, strikes, and listed controllers; Pioneer configures access and alerts. Exterior / life-safety doors stay on listed hardware — not hobby boards as the system of record.
Emergency command modes
Full lockdown orchestration and fire-panel (FACP) integration need district policy plus AHJ / fire authority buy-in — so they are not required on the first install. Phase 1 is cameras, access, network, and Care. When you are ready, modes stay distinct (lockdown ≠ fire) and egress stays exit-out, not open-entry-in. See Emergency modes.
AdGuard
Local DNS filtering to block malicious and inappropriate destinations across VLANs — the category role often filled by cloud DNS products.
WireGuard
Care remote access is a locked tunnel with keys on a few approved devices — not a public password portal and not the whole IT department. Revoke a device by deleting its peer. Staff day-to-day stays on-site; Care is for ops. See Hardening.
Suricata
IDS/IPS integrated with the OPNsense edge. Watches traffic for attack patterns in real time and supports the segmented design.
Grafana
Dashboards and alerts for system health, uptime, and operational signals — so facilities and IT see the same picture.
Seven VLANs
Management, cameras, access control, staff, student/guest, servers, and IoT — each isolated by policy. Cameras and door controllers do not share a flat free-for-all with student devices.
Encrypted backups
Encrypted backup routines for configurations and critical data so a failed disk or closet incident does not erase the school’s security posture.
Raising the bar on the hard legs
Local-first already cuts remote live-view and vendor-cloud blast radius. These practices harden the remaining paths — stolen Care devices, ransomware already inside, and physical closet access — without changing the own-it platform model.
Phase 1 (every install)
- Care keys: few named devices only (not the whole IT dept); revoke by deleting a peer; staff use on-site dashboards, not permanent Care tunnels; FileVault on the Mini; optional hardware key / passkey for Care operators.
- Containment: camera / access / brain VLANs with default-deny between staff devices and camera storage; Mini stays minimal (no email client); Suricata watching weird lateral noise; encrypted offsite backups so a closet incident is not a total loss.
- Closet: locked rack; badge (and camera) on the network closet where scoped; unused switch ports shut; guest Wi‑Fi never shares the camera VLAN.
Phase 2 (when the district is ready)
- 802.1X on staff drops; stricter MAC policies; richer audit of who badged the closet / who opened Care.
- Short-lived Care peers on a rotate schedule; district SSO + MFA for any web UI inside the tunnel.
Honest ceiling: insider risk and “human with a key” never go to zero. Phase 1 makes those legs clearly harder than a flat network plus a shared cloud password — including campuses where motivated students can attack the stack themselves.
Role clarity: Pioneer is not the low-voltage contractor. Physical cameras, cabling, readers, and strikes are installed by a certified partner. Pioneer owns design, software configuration, grant filing from your brief, and the client relationship.