Skip to main content
Bookcase Pro
Student information system for institutions of 300 to 5,000 students

Prove what happened. File it correctly. Set it up yourself.

Bookcase Pro is a student information system built so that every record change is permanent, every regulator report can be regenerated exactly as it was filed, and every migration can be done by your registrar instead of a consultant. Published pricing. No quote cycle. No implementation contract.

Filing guides in review — available before launch

Dual Verification Architecture: Immutable Audit Log & National Submission Validator
Student Record · Event Stream
Compensating Event · Prior Value Preserved
Student Subject Maya Lin (STU-88219)
Event Type GradeCorrectionRecorded
Field modified: CS301 · Advanced Data Structures
Prior recorded value: B+ (3.30)
Compensating value: A- (3.70)
Reason: Instructor Grade Appeal Resolution (Board Ref #4410)
Actor: registrar@institution.edu (Registrar) Hash: sha256:7f83b165...c992
Statutory Engine
Target National Ledger: PDDikti Feeder / Neo Feeder 2026-1
Audit Verdict Submission Blocked · 1 Hard Failure
Completeness 98.4%
Uniqueness 100%
Coherence 99.1%
Validity 97.2%
Pre-submission automated audit: 3 row checks
  • ✓ Row 104: NIK Format Check — 16 numeric digits validated against Kemendikbud schema
  • ✓ Row 105: SKS Kurikulum Alignment — Credit count resolves to prodi study plan rules
  • ✕ Row 106: NIK Structural Check — Found 15 digits (must be 16). Blocks statutory package generation.
Hard failure policy: Submission locked until NIK is resolved Zero silent data loss

Architectural Guarantees & Operating Invariants

  • Event-sourced records: no destructive update path exists in the system
  • Native submission generation for PDDikti, HEIDA, PACE, AISHE/ABC, and IPEDS
  • WCAG 2.1 AA with blocking accessibility gates on every release
  • Self-serve migration with a reversible dry run
  • Pricing published: approximately $49, $22, or $12 per student per year by country band
Systemic Structural Gaps

Four failures every registrar recognizes

None of these are software preferences. They are structural failures in how student information systems are built and sold, and every one of them lands on the same three or four people on your campus.

Domain Invariant Violation
01

The record cannot defend itself

Your SIS lets someone overwrite a grade, a credit total, or an enrollment status, and the previous value is gone. When an auditor, an accreditor, or a ministry asks what you reported in a prior cycle, you reconstruct it from spreadsheets, email threads, and memory. In Indonesia, deleting reported data is not merely bad practice; it is prohibited, and correction is permitted only through national validation. Most systems on the market were not designed for that reality.

Statutory Architecture Gap
02

Statutory filing is a manual project every cycle

PDDikti Feeder, CHED HEIDA, PACE, AISHE and ABC, IPEDS. Every one of these is mandatory, on a fixed calendar, with hard validation and real consequences. India’s ABC upload windows close permanently. Mexico requires enrollment counts to reconcile within 30 days of cycle start. Yet no major vendor generates these artifacts natively. Your registrar exports to Excel, reformats by hand, submits, and hopes.

Category Lock-In Strategy
03

You cannot leave your current vendor

A mid-sized institution typically carries 15 to 30 direct system integrations and 50 to 100 or more data flows, most of them undocumented. Migration analysis of the category consistently finds integration work driving 30 to 50 percent budget overruns when planning starts late. The incumbent knows this. Switching cost is the product.

Enterprise Queue Neglect
04

You are too small to be a priority

Enterprise vendors migrate a small fraction of their own installed base each year and are now absorbing hundreds of additional accounts from a competitor’s bankruptcy. If you enroll 800 students, you are not at the front of that queue and you will not be. Meanwhile the affordable alternatives are built around one country’s assumptions: one language for support, one set of payment rails, one regulator.

We built Bookcase Pro against these four problems specifically, and declined to build most other things. That trade-off is stated plainly further down this page.

See fit & scope boundaries
Capability one

Nothing is ever overwritten. Everything can be reproduced.

Bookcase Pro stores every change to a student record as an immutable event: what changed, who changed it, when it happened, when it was recorded, and why. There is no code path in the system that updates or deletes a domain event, and our build pipeline fails if an engineer introduces one.

That single architectural decision produces four things a conventional SIS cannot offer.

01

Point-in-time reproduction

Regenerate any report for any prior date and get back the same artifact you originally filed, verified by stored hash comparison. Not an approximation assembled from current data.

02

Correction without erasure

A corrected fact is recorded as a compensating event. The prior value stays retrievable with its actor and timestamp. This is what Indonesian regulation requires, and it is how the system works everywhere.

03

Complete provenance on every field

Every value on a student record can be traced to the event that set it, including values imported during migration, which carry their source system with them.

04

Erasure that does not break the chain

When a student exercises a deletion right under CCPA, LFPDPPP, the Philippine Data Privacy Act, India’s DPDP Act, or Indonesia’s PDP law, we destroy that subject’s encryption key. The personal data becomes unrecoverable; the record chain and its integrity remain intact.

Statutory Legislative Precedent
"Permendikbud 61/2016 prohibits the deletion of reported higher education data and permits correction only through national validation. A national regulator has effectively legislated the way this system already works."
Permendikbud 61/2016 · Ministry of Education, Culture, Research, and Technology (Indonesia)
APPEND ONLY
E-09411 · Original Enrollment 2024-09-01

Initial term enrollment recorded: 15.0 credit hours

E-10492 · Course Grade Stored 2024-12-18

CS301 grade committed: B+ (3.30)

E-14902 · Compensating Correction 2026-03-14

Grade adjusted to A- (3.70). Prior record E-10492 remains untouched in the Merkle log.

Capability two

Your statutory filing, generated by the system that holds the data

Every Wave 1 country outside the United States runs a mandatory national data ledger. Every institution must file into it on a statutory cadence. As far as our own competitive review can establish, no major vendor publishes native submission generation for any of them. That gap is the reason this product exists.

Bookcase Pro generates the regulator’s actual artifact, validates it against published field rules before you can submit, blocks submission on any hard failure with row-level error detail, records the submission as a permanent event, and can regenerate that exact file later.

Statutory filing generation matrix across Wave 1 countries
Country National System What Bookcase Pro Generates Statutory Cadence
🇮🇩 Indonesia ID PDDikti Feeder / Neo Feeder Feeder-format submission scored against all four PDDikti data-quality dimensions: completeness, uniqueness, coherence, validity Semesterly, ganjil and genap checkpoints
🇵🇭 Philippines PH CHED HEIDA / HEMIS HEIDA-format submission with prior-period context preserved Per CHED memorandum cycle
🇲🇽 Mexico MX PACE and SEP RVOE Enrollment reconciliation artifact aligned to the 30-day cycle-start requirement Within 30 days of each cycle start
🇮🇳 India IN AISHE Web DCF, ABC and APAAR DCF submission plus ABC credit deposit records with APAAR identifier validation Annual, with permanent window closure
🇺🇸 United States US IPEDS IPEDS collection artifact Annual and term-based
Validation Invariant Demonstration

Entry-Time Structural Identifier Validation

Bad identifiers are rejected as typed — never discovered on filing deadline day.

Found 15 digits (requires exactly 16). Blocks statutory submission.
Invariant 01

National identifier validation at entry and at submission: 16-digit structural validation for NIK, structural validation for CURP, presence and format checks for APAAR. Bad identifiers are caught when they are typed, not on filing day.

Invariant 02

Country profiles are versioned data, not code. Grading scales, credit systems, term structures, identifier rules, labels, and submission field mappings change without a software release. When a regulator changes a format, you are not waiting on our deploy schedule.

Invariant 03

Every submission is an event. You will always be able to answer what you filed, when, and who approved it.

Free Country Filing Guides

Our filing guides are written in-language and free to use whether or not you ever become a customer.

Read the filing guide for your country
Capability three

Migrate yourself. No consultant, no statement of work, no implementation year.

Migration difficulty is the real lock-in in this category, so we attacked it directly. A registrar with no engineering support should be able to move an institution’s records into Bookcase Pro and verify the result independently. That is a product requirement we are held to, not a service we sell.

1 Phase 01

Inspect the source

Point the tool at your existing system’s export or database. It reads the schema and reports what it found, including tables and fields you may not know are in use.

2 Phase 02

Map the fields

Guided mapping with suggested matches for common systems. You confirm or override; nothing is inferred silently.

3 Phase 03

Run a reversible dry run

The import executes against a staging instance. You review it as real data. Then you reverse it completely if you want to change anything.

4 Phase 04

Reconcile row by row

Every import produces a reconciliation report at row level: what came in, what was rejected, and why. No import is declared successful on a summary count.

5 Phase 05

Commit with provenance

The final import is committed as an event batch. Every migrated value keeps its source system attribution permanently.

Tooling Invariant: Reversible Dry Run (Phases 03 & 04)

Row-Level Import Reconciliation Report

1,246 Valid Rows 2 Flagged Rows
Source Line Entity Legacy Key Mapping Status Reconciliation Detail
Row #0411 CourseEnrollment CRS-BANNER-810 ✓ MAPPED Staged into staging dry-run instance; Merkle hash verified.
Row #0412 StudentBirthdate STU-LEGACY-004 ✕ REJECTED Found invalid legacy value 00/00/0000. Rejection isolated; import continues.
Row #0413 TranscriptRecord TRN-LEGACY-904 ✓ MAPPED Prior grading scale normalized with permanent source attribution.
Rollback guarantee: 1-click total dry-run evacuation leaves production zero-dirty. Provenance preserved: "Source: Banner 9 Export 2026-Q1"
Pre-Migration Risk Mitigation

Integration inventory template

Before you migrate, the integration inventory template surfaces the undocumented data flows that cause budget overruns when they are discovered late: the nightly file to the library system, the finance export nobody owns, the report someone built in 2019 that a dean still uses.

Published Customer Covenant

Anti-lock-in commitment

We will not use migration difficulty as a retention strategy, because we are using it as our entry strategy and cannot credibly do both. Full data export on demand is a published commitment, not a support request. If you leave, you leave with everything, in a documented format.

Explore the Self-Serve Migration Process in Detail

See step-by-step schema analysis, dry-run reconciliation, and automated rollback tooling.

See the migration walkthrough
How it behaves when things are not ideal

Designed for the registrar’s office as it actually is

Most SIS products assume broadband, a large monitor, a quiet week, and a mouse. Registration week is none of those things, and neither is a satellite campus.

Works offline

Core registrar workflows keep working when the network does not. Commands queue locally with idempotency keys and sync on reconnect. Conflicts are surfaced for a human to resolve rather than silently resolved in the background. The Philippine regulator ships its own offline tool precisely because vendors do not; we would rather you not need it.

Survives registration day

Every course section is coordinated by a dedicated concurrency controller, so simultaneous registration into a full section cannot oversell a seat. Waitlist promotion is deterministic and strictly ordered. This is load-tested against realistic peak patterns, not assumed.

Accessible by default, not by remediation

WCAG 2.1 AA, with automated checks for keyboard navigation, reduced motion, and non-visual chart alternatives running as blocking gates on every pull request. A published VPAT is part of our year-one commitment. For US public institutions working against ADA Title II deadlines, this matters more each quarter.

Runs on modest hardware and slow links

Fully operable at 1024x600 and on a throttled connection. Every interactive flow completes by keyboard alone. Public pages ship at or under 90 KB of initial JavaScript, and the application at or under 200 KB, because bandwidth is a real cost in most of the markets we serve.

Empirical Benchmarks

Performance commitments

Read operations at or under 400 ms p95 and registration at or under 800 ms p95 under our defined 10,000-user load profile. These are the numbers we test against and will publish results for.

≤ 400 ms p95 read operations
≤ 800 ms p95 registration ops
10,000 concurrent user profile
≤ 90 KB initial page JavaScript
International-First Architecture

Localization on three independent axes

Axis 01 Interface language, chosen per user: English, Bahasa Indonesia, Filipino, and Spanish
Axis 02 Country profile, set per institution, governing identifiers, credits, grading, terms, and submissions:
Axis 03 Formatting locale, governing dates, numbers, currency, and name ordering:
Selected Locale Output: March 14, 2026 $49.00 USD Spring 2026 Semester
Zero client recalculation drift

Interface available in English, Bahasa Indonesia, Filipino, and Spanish. Support language coverage is being confirmed; we will state it here as a fact only after our Support Lead validates it.

Pricing

One price. Whole product. Published on the website.

Bands are assigned by national purchasing power, not by feature gating. Every band receives the same product, the same country profile depth, and the same submission engine. Bands differ in price and in support entitlement only.

Band A United States
$49 / student / year

Example 600 students: approximately $29,400 per year

What is included:

Full product, all country profile depth, submission engine, migration tooling, updates

Band B Mexico
$22 / student / year

Example 600 students: approximately $13,200 per year

What is included:

Full product, all country profile depth, submission engine, migration tooling, updates

Band C Indonesia, Philippines, India
$12 / student / year

Example 600 students: approximately $7,200 per year

What is included:

Full product, all country profile depth, submission engine, migration tooling, updates

Interactive Cost Model

Estimate your annual invoice in 5 seconds

Slide to your institution's headcount (300 to 5,000 students). Whole product included in all bands.

800
Band A (US) $39,200 $49 / student / yr
Band B (Mexico) $17,600 $22 / student / yr
Band C (ID, PH, IN) $9,600 $12 / student / yr
Unconditional Transparency

What is not on this page, because it does not exist

  • No add-on modules: Invoicing, transcripts, CRM, and branding are not separate line items. Competitors charging roughly $75 per month per module are the pattern we refused to copy.
  • No implementation fee: Migration is a product, not a service engagement.
  • No quote cycle: If you can count your students, you can calculate your invoice.
  • No multi-year lock: No multi-year contract required to get the published price.
Zero-Commitment Evaluation

Free tier: Synthetic data sandbox

A sandbox with synthetic data, open to anyone, no sales conversation. Load your own sample data, run a dry-run migration, generate a submission artifact against synthetic records, and decide for yourself.

Status, stated honestly

What we have built, what we have not, and why we are telling you

Most vendor websites imply a maturity they do not have. Ours will not, because the buyers we want are the ones who check.

Shipped or committed for year one

7 items
  • Event-sourced record core with point-in-time reproduction and crypto-shredding (in active build)
  • Country profiles for Indonesia, the Philippines, Mexico, India, and the United States — in active build at full submission depth
  • Self-serve migration with reversible dry run and row-level reconciliation (in active build)
  • Offline registrar operation and load-tested registration concurrency (in active build)
  • WCAG 2.1 AA with blocking accessibility gates on every release (committed; VPAT publication is a year-one commitment)
  • SOC 2 Type I is a year-one commitment, with Type II initiated after (not yet complete — see below)
  • Per-institution database isolation with drilled per-tenant backup and restore

Not true yet, and we will not imply otherwise

6 items
  • No SOC 2 report is complete today
  • No public reference customers yet; the design partner program is how that changes
  • No financial aid processing, including FAFSA and ISIR
  • No alumni or advancement module
  • No learning management system; we integrate with Canvas and Moodle instead
  • Hard data residency is a guarantee only in FedRAMP jurisdiction. Everywhere else we place data in the closest supported region on a best-effort basis and document exactly where it lives. Our sales team is instructed never to describe that as a guarantee.
Cohort Recruitment

Design partner program

We are recruiting a small number of design partners, with a deliberate majority outside the United States. Partners get materially discounted multi-year pricing, direct influence over their country profile, and a named engineer. In exchange we ask for public reference rights and honest feedback. You would be taking a real risk on a pre-production platform, and the pricing reflects that rather than pretending otherwise.

Fit

Who this is for, and who it is not for

Bookcase Pro is a strong fit if

  • You enroll roughly 300 to 5,000 students, on one campus or several
  • You operate in Indonesia, the Philippines, Mexico, India, or the United States
  • Statutory or accreditation reporting is a recurring source of stress
  • You have been told an enterprise migration will take 12 to 18 months and cost six figures
  • You want to evaluate software without entering a sales process
  • Your team includes people who will use the system in a language other than English

Look elsewhere if

  • Financial aid processing is a requirement this year. We do not do it, and we will lose deals over it.
  • Alumni fundraising and advancement must live in the same system
  • You need a learning management system rather than an integration with one
  • You enroll more than 5,000 students
  • You require a contractual data residency guarantee outside the FedRAMP jurisdiction
  • You need a vendor with a decade of references today. We do not have that, and we are not going to imply that we do.

"We would rather you disqualify yourself in ninety seconds than spend three months discovering the same thing."

Direct Answers

Questions we get asked, answered directly

Candid answers to the hardest questions registrars and institutional leaders ask us.

01 Is Bookcase Pro live? Can I run my institution on it today?

Not yet. We are in active build with design partners and the sandbox is open with synthetic data. First statutory submission cycles ship with our design partner cohort. If you need a production system this term, we are not the right choice, and we will say so on the call.

02 What does "point-in-time reproduction" actually mean in practice?

Ask the system for the enrollment report as of a date two years ago and you receive the same file you filed then, verified by a stored hash comparison, including any records that were later corrected. It is not the current data filtered by date. It is the historical state, reconstructed from the event log.

03 If nothing can be deleted, how do you handle a student’s deletion request?

Each subject’s personal data is encrypted with a key unique to that subject. An erasure request destroys the key. The personal data becomes permanently unrecoverable while the event chain, its sequence, and its integrity hashes remain intact. Projections stay readable with tombstone labels so downstream reports do not break.

04 Do you actually generate the PDDikti Feeder file, or just an export I have to reformat?

The regulator’s actual artifact, validated against published field rules before submission and scored against all four PDDikti data-quality dimensions. If validation fails, submission is blocked and you get row-level detail on what to fix.

05 What happens when a regulator changes the submission format?

Country profiles are versioned data, not code. Field mappings, validation rules, grading scales, and labels change without a software deploy. Each of our five profiles has a named owner and a quarterly regulatory review.

06 How long does migration take, and what does it cost?

It costs nothing beyond your subscription, because it is a product feature rather than a service. Duration depends on the state of your source data, which the inspection step reports honestly before you commit to anything. The measure we hold ourselves to is that a registrar completes it with zero engineering intervention from us.

07 Where is my data stored?

In an isolated database dedicated to your institution, placed in the closest supported region for your jurisdiction, and documented for you explicitly. A hard jurisdictional guarantee is available only in the FedRAMP jurisdiction. Everywhere else placement is best-effort. We will not describe it as anything stronger.

08 Do you have SOC 2?

Not today. SOC 2 Type I is a year-one commitment with Type II initiated after. HECVAT 4.x publication is planned and pending; we will link it here once it is confirmed published.

09 Why is your pricing lower than everyone else’s?

Because our delivery model is self-serve and our architecture runs at the edge without per-institution infrastructure overhead. We are not discounting a services business; we do not have one. The trade is real: you get software and documentation rather than an implementation team.

10 Why is the price different by country?

Bands follow purchasing power, not features. An institution in Band C receives exactly the same product and the same country profile depth as one in Band A.

11 Can I get my data out if I leave?

Yes, on demand, in a documented format, as a published commitment. We are using migration difficulty as our way into this market, so we cannot honestly use it as a way to keep you.

12 Do you integrate with our LMS?

Canvas and Moodle. We are not building a learning management system and do not intend to.

13 Is the interface available in my language?

English, Bahasa Indonesia, Filipino, and Spanish at launch, with support delivered in all four. There are no hardcoded strings, and formatting for dates, numbers, currency, and name ordering follows your locale rather than ours.

14 What if my institution has more than 5,000 students?

We are not the right fit this year. The 5,000-student ceiling is a deliberate scope boundary, and we would rather hold it than fail you at scale.

Immediate Evidence

Start with synthetic data. Decide with evidence.

No demo request form standing between you and the product. Open a sandbox, load sample records, run a reversible migration dry run, and generate a submission artifact for your country. If it does not do what this page says, you will know within an hour.

Notice: Bookcase Pro is pre-production. Sandbox environments use synthetic data only. No live student records are accepted before our data processing, residency, retention, restore, and incident readiness gates are passed.