Nemesis — Secure Learning Environment
Nemesis
Nemesis — Enemy to Ignorance Nemesis owl logo icon — owl in graduation cap on grey shield with gold border
NEMESIS
Enemy to Ignorance

A plain-English guide

Every school in America needs to protect its students online. Most can't afford to. Nemesis changes that.

Government guardrails don't teach responsibility. Education does.

Content filters block websites. They don't teach children why some websites are dangerous.

Firewalls block threats. They don't teach users what a threat looks like.

Compliance mandates check boxes. They don't build capability.

A child who understands why personal information is valuable protects it instinctively. A child who is simply blocked from sharing it finds another way.

A parent who understands what a phishing attempt looks like is protected everywhere. A parent whose email filter catches phishing is protected only there.

An IT coordinator who understands their network makes better decisions every day. An IT coordinator who follows a compliance checklist makes better-documented decisions.

Nemesis SL was built on a different premise:

The goal is not compliance. The goal is capability.

We protect immediately. We explain clearly. We teach permanently.

In every alert. In every diagnostic. In every AI response. In every learning module.
For every user. At every level. In their language.

This is the design target behind every feature in this document, not a claim that it's fully realized yet. It's real and shipping today for the diagnostic library (19 of 19 checks tiered) and for a substantial, still-growing share of the alert system — see "Accessibility by design" and "The diagnostic library" below for the measured state, not asserted as complete here.

Because the families and schools that need security most are the ones who can least afford to hire someone who already understands it. We built Nemesis SL so they don't have to.

Every piece of this already exists somewhere, sold by a different company, to schools that can afford it.

Network security

Cisco, Fortinet, and similar

Cost$3,000–8,000/yr
Self-hostedNo
Works at homeNo
Covers personal phonesNo
Who has itLarge districts only

Content filtering

Securly, GoGuardian, and similar

Cost$2,000–5,000/yr
Self-hostedNo
Student dataStored by vendor
Covers personal phonesNo
Who has itWell-funded schools

AI learning assistant

Khan Academy, Khanmigo, and similar

Cost$5,000–15,000/yr
Works with school's own curriculumNo
Adapts to each studentLimited
Who has itWealthy districts

Teacher lesson-planning tools

Chalkie, and similar

What it doesHelps teachers generate lesson plans and worksheets faster with AI
Who has it1M+ teachers, 100+ countries ($4M funded)
Device/network enforcementNone
Built-in curriculumNone — teacher still writes the content
On-premise optionNo

A teacher productivity tool, not a school platform — it doesn't compete with Nemesis so much as it could one day feed content into it.

Translation services

Various vendors

Cost$10,000+/yr
AutomaticNo — manual process
Who has itLarge urban districts

Emergency response

Raptor, Navigate360, and similar

Cost$3,000–8,000/yr
Integrated with the networkNo
Who has itWell-funded schools

Personal phone control, without confiscation

Partial: LockedIn (app, launched March 2026)

Requires an app on the phoneYes
Cost$5–20 / student / yr
Student dataStored by the startup
PrivacyGPS tracking, 24/7
ReviewsPoor
Network-level, no appNo — nobody does this yet

And the learning platforms, on top of all of that

These are the tools schools already buy to teach with. They are good at what they do. None of them touches security, and none of them is self-hosted.

Adaptive practice — math & language arts

IXL

Cost$24.50 / student / yr
A 500-student school pays$12,250 / yr — for IXL alone
Network securityNone
ESL reading supportNone
AI safety curriculumNone
Career guidanceNone
On-premise optionNo — data leaves the school

Strong drill-and-practice engine, used by millions of students. Price verified: Wichita Falls ISD board approval, 2026 — 9,200 students, $227,895 total.

Grammar & writing

NoRedInk

CostCustom quote — contact vendor
Network securityNone
ESL reading supportNone
AI safety curriculumNone
On-premise optionNo

Popular with ELA teachers, strong writing instruction. No published price — we are not estimating one.

ESL / newcomer language learning

Summit K12

CostCustom quote — ESL focused
Network securityNone
AI safety curriculumNone
On-premise optionNo

Strong ESL instruction for newcomers. No published price — we are not estimating one.

The Nemesis difference. A school using IXL, NoRedInk and Summit K12 is paying for three separate platforms, three separate logins, three separate data silos — and still has no network security solution.

Nemesis replaces all three education platforms and the network security product — in one installation, on the school's own hardware, with one teacher dashboard and one student login. At a price point well below what schools currently pay for these tools separately. Stated as the positioning claim it is: the AI-safety curriculum, translation and security are working today; the reading and full-subject curriculum that would replace an ELA or math platform outright are the planned phases in section 08, not shipped capability.

COMPETITOR pricing — what a school pays today for all of the above

$23,000 – $51,000 / year

These are competitors' figures, not Nemesis pricing. Nemesis pricing is in section 06.

  • 5–6 different vendors
  • Student data stored at every one of them
  • Protection stops working the moment a device leaves the building
  • None of it is self-hosted

We build what we can own. We choose vendors deliberately when we need them. And we always have a plan to replace what we license.

Where we use vendors today: Amazon Polly for voice synthesis — removing this weekend after we record our own. Anthropic Claude API for AI features — chosen deliberately for quality, not because we couldn't build something else. The AI is the product's brain. We chose the best brain available.

The principle is not “license nothing.” The principle is: own everything that defines the product. Choose vendors only for what doesn't.

A vendor can change their TTS pricing. They cannot change our curriculum. They cannot change our security platform. They cannot change our agents. The pieces that make Nemesis SL what it is: those are yours. Permanently.

The principle behind every decision: we build what we need, we own what we build, we support what we own.

Voice synthesis: we could have licensed AWS Polly permanently. We're building our own instead — not because Polly doesn't work, but because we don't want to own Polly's pricing decisions or its deprecation schedule.

Attendance: the easy path is a permanent connector to Skyward or PowerSchool, dependent on someone else's API changes forever. We're building our own attendance module instead, with connectors to those same systems offered as a bridge for schools that aren't ready to convert — not as the destination.

Our founder spent years at ADP and watched what happened to businesses running one integrated system versus businesses managing vendors who blamed each other when something broke. The lesson wasn't about payroll — it was about ownership. Own what you build. Build what you need. Never depend permanently on what you can't control.

One system. One owner. One team to call when something breaks. That's the architecture, and it's the company.
The voice engine and attendance module follow this principle as design direction, not as claims that either is built today: voice synthesis runs on placeholder browser TTS right now (see "Reading and language learning" above), and the attendance module is Phase 2, post-funding, zero code yet (see section 08).

One device, about the size of a small book. It plugs into the school's existing network. The school buys it once. They own it. They control it. Student data never leaves the building.

NETWORK $$ FILTERING $$ LEARNING $$ TRANSLATION $$ EMERGENCY $$ PHONES (partial) $$ 6 vendors, your data with each Nemesis Protected students Informed parents Focused teachers
✅ Working today 🔨 Being built now 📋 Planned, after funding

Network protection

✅ Working
Internet Nemesis Safe content reaches students Dangerous content blocked automatically

Blocks harmful websites automatically, updated daily with new threats. Works whether the student is at school, or at home on a school-owned laptop.

Firewall rule management

📋 Planned

IT directors get full visibility and control over every firewall rule on the Nemesis appliance, from the dashboard — no command line needed.

  • View. All active rules in a clean dashboard table, grouped by allowed/blocked, inbound/outbound, and protocol.
  • Create. A simple form for new rules — source, destination, port, protocol, action.
  • Manage. Enable, disable, or delete rules from the dashboard; changes take effect immediately.
Not yet built — the backend design work is only just starting as of this writing. The underlying firewall chokepoint it will sit on top of (firewall.py) is real and already enforcing rules today; this is a management UI for it, not a new enforcement mechanism.

AI learning assistant

✅ Working
QUIZ AI assistant works WITH the student — never hands over quiz answers

An AI helper that works with students on their lessons — not doing the work for them. Students must complete their lesson to earn access to it.

At a time when students are being told AI will eliminate their career options, Nemesis teaches them to be the people who build, secure, and direct AI systems. The students who understand AI will give instructions to AI. The students who don't will receive instructions from people who do. Every lesson connects to real IT careers that are growing because of AI, not despite it.

Accessibility by design

✅ Working

Home users don't run high-end security software — not because they don't care, but because they don't understand it. A parent who sees "Suspicious outbound UDP/53 to known malicious infrastructure" does nothing, not because they aren't worried, but because they don't know what it means or what to do about it. The threat continues. The protection fails — not because the software failed, but because it spoke a language the user didn't speak.

Nemesis solves this the way differentiated instruction solves it in a classroom: the same alert, translated into the language the person reading it actually speaks.

Illustrative example — same underlying detection, three renderings:

Beginner: "A device tried to contact a dangerous website. We blocked it. Your family is safe. [Tell me more] [Got it]"

Intermediate: "DNS query to known malicious infrastructure blocked. Device flagged for review. Confidence: HIGH."

Expert: "UDP/53 outbound to 185.220.101.47 (Tor exit node). AbuseIPDB confidence: 97. Device quarantined pending review." Illustrative, in this document's own established convention for examples like this (see the AI usage intelligence section above) — not a captured screenshot. The AbuseIPDB confidence score and the quarantine action are real, live integrations; the specific IP and wording here are constructed to show the shape, not copied from a real incident.

The parent acts. The IT coordinator investigates. The security professional responds. One click, saved in the browser, live on every page — a parent in a rural community without IT training gets the same protection and the same understanding as a corporate IT director. Technical awareness shouldn't determine whether a family is protected online.

The setting lives entirely in the browser — never written to the server or the user's session — so it can't be intercepted or overridden server-side, including on a demo or sandboxed install. Coverage today is partial: a substantial share of dashboard text is already tiered this way, but not every element has all three versions yet, and the exact share hasn't been fully measured. This document won't claim "everywhere" before that's true.

The diagnostic library

✅ Working

Every tool Nemesis uses to monitor your network is also a lesson. 19 built-in diagnostic checks — hardware load, disk space, VPN status, DNS health, firewall rules, and more — each one a real window into how your network actually works, not a marketing article about it.

Each check already carries three genuinely distinct explanations of what it does and why it matters — plain English, a technical summary, or the full technical detail — the same Expertise Chooser that changes how alerts read changes how these read too. One click runs any check and shows the real output, live, next to whichever level you've chosen.

Ask the built-in assistant a plain-language question — "why does my internet feel slow?" — and when a specific check would answer it, the assistant names it by name and says what to look for in the output, instead of guessing or sending you to search the web. The assistant recommends which tool to run and how to read what it returns; it doesn't run the tool for you or generate a fresh interpretation of that specific run's numbers. The three-tier explanations are written once, by hand, not regenerated live — the "why it matters" is real, it just isn't dynamic.

For the curious home user: a path from "my internet seems slow" to understanding load averages, memory pressure, and VPN tunnels — because they wanted to, not because they had to. For the school IT coordinator: every system they manage, explained without a computer science degree standing between them and the answer.

No extra subscription. No separate app. Built into the product you already run.

For students — focused learning time

✅ Working

Students are limited to educational tools during learning time — no social media, no distractions, no off-topic browsing while lessons are active.

Beyond dangerous content, unprotected school networks allow:

  • Social media during class (Instagram, TikTok, Snapchat)
  • Entertainment and gaming sites
  • AI tools that complete homework and essays for students — undermining learning and academic integrity
  • Any distraction a student can find on the open internet

Nemesis blocks all of it during learning time. Students stay on task. Teachers maintain classroom focus. Parents know their child is doing their own work. Academic integrity is enforced at the network level — not by asking students to comply, but by making non-compliance impossible.

Scope, stated because the rest of this document is specific about it: "at the network level" means traffic that crosses the school network or an enrolled school-owned device. A personal phone on its own cellular data is outside that path until the network-level phone control below is built — which is exactly why that item is on the roadmap.
Nemesis enforces academic integrity at the network level — not just in the classroom app. Social media, entertainment, and gaming sites are already blocked on enrolled devices during learning time — not by an honor code, but by the network itself. Named AI chat services (ChatGPT, Character.AI, Claude, Gemini, Copilot) are blocked the same way, today. The one AI a student can reach on an enrolled device is Nemesis's own lesson assistant — gated behind finishing the lesson, and built to work with a student rather than hand over answers. 🔨 Building, not yet shipped: catching an AI-misuse attempt and redirecting the student straight back into the curriculum, instead of just blocking the site. That's the homework-integrity system already on this document's own roadmap (see "Homework assistant" below) — real and scoped, not a working feature yet, and this document won't claim otherwise before it is.

For teachers — data-driven instructional reporting

🔨 Building

Data-driven instructional reporting built into every lesson — teachers see exactly what each student struggled with and what to teach next.

Quiz scoring is live today. The reporting layer that turns it into a teach-next recommendation is in build for the October demo.

Unlimited language translation

✅ Working
Lesson Español Tiếng Việt 中文 العربية Kreyòl Tagalog Français + any other

Nemesis translates into any language Claude knows — 200+ languages and dialects. Schools configure which languages they actively use.

A Vietnamese-speaking student gets the same lesson as an English-speaking student — automatically, at no extra cost. Adding a language is a configuration change, not a development project: there is no language pack to install and no per-language engineering work.

⛔ Current state, found 2026-09-19 — the architecture works; the stored catalog does not, right now. All 43 currently-stored translations (17 Spanish, 17 Vietnamese, 9 Arabic) fail the reader's own paragraph-alignment check, because a lesson-content rebuild (Sept 18-19) restructured every lesson after the translations were written (Sept 15). A student selecting a language today sees "This translation is out of date with the lesson and cannot be matched to the slide on screen" instead of the translated text — the safety check working correctly, not a bug in it. Not fixed overnight, deliberately: re-translating resets the 17 approved Spanish lessons to unreviewed status, discarding Angie's approval — a content decision for Paul and Angie, not an engineering one. Full detail: PUNCHLIST.md.

Device protection at home

✅ Working
School Home Anywhere else

When a school laptop goes home, the protection goes with it — same blocking, same monitoring. The protection lives on the device, not on the building.

Applies to enrolled, school-owned devices.

Component monitoring

✅ Working

Nemesis monitors every device for missing or compromised security components. ClamAV removed by a student. A security engine that goes absent after a Windows update. Component inventory that changes unexpectedly. Nemesis detects it on the next heartbeat and alerts the administrator immediately.

The administrator sees which device has the problem, exactly what is missing, and how long it has been missing. Detection is instant and certain — the administrator knows before the teacher does.

Remote recovery

📋 In development — roadmap

Automated remote recovery is on the active development roadmap. When complete, administrators will be able to trigger a full component reinstall from the dashboard, delivered silently to the device.

Expected: pre-release. Detection (above) is live today; remote recovery is designed, not yet built.

Parent visibility

🔨 Building

Parents will see what their child is doing on school devices — in their own language, on their phone.

Student social platform

🔨 Building

A school-safe version of social media. Students can only access it after completing their lessons.

Emergency response

🔨 Building

One button locks down the school. First responders scan a QR code for safe access.

Homework assistant

🔨 Building

Students get AI help with homework. The system watches for integrity concerns and notifies the teacher — without accusing the student.

Bring your own lesson

🔨 Coming Soon

Teachers will be able to upload their own lesson content directly into Nemesis. Upload a text file or document — Nemesis processes it automatically:

  • Key points marked with the Nemesis owl callout
  • Audio narration generated
  • Quiz questions created from the content
  • Translated into all 5 languages

The teacher reviews and approves everything before it goes live to students. The teacher writes the lesson. Nemesis handles the rest.

Not shipped yet — described here so it isn't confused with what students and teachers can use today.

Multi-platform agent coverage

One protocol, one dashboard, multiple platform implementations. The Windows agent solved every hard design problem — attestation, tamper detection, telemetry, dashboard integration; the remaining platforms are translation work against that protocol, not new design work.

  • Windows. ✅ Working Full agent — TPM-backed binary attestation, memory injection detection, tamper detection and alerting, persistent tray icon (the owl), heartbeat telemetry, dashboard integration. 1.0.14 build pending staging. Peer-to-peer enforcement: 🔨 in active development (WinDivert layer).
  • Linux. 🔨 Building Core components exist today (DNS enforcement, TPM attestation, memory scanning, behavioral monitoring deploy scripts, all confirmed present in the repo). Full feature parity with the Windows agent is not yet verified — an audit is in progress. Target: demo-ready October 6. Peer-to-peer enforcement: 📋 designed (privileged helper), not built.
  • Android. 🔨 Building Zero code in the repo as of this writing. Full build starting this week: enrollment + heartbeat (week 1), Play Integrity attestation (week 1, hardware-backed, cannot be spoofed), persistent notification (week 1), full tamper detection (week 2). The Windows agent protocol is the spec; this is a port, not a redesign. Peer-to-peer enforcement: 📋 designed (reporting only at this stage).
  • Chrome extension. 📋 Planned Zero code in the repo as of this writing. Specification complete; build starts once the Android build stabilizes. Target: October 6 demo. Deployment path: Google Admin Console. Peer-to-peer enforcement: 📋 designed (the appliance enforces for this platform, not the agent).
  • iOS. 📋 Planned Apple certification in progress. Expected Q1 2027.
"Working" is reserved for what the repo actually contains as of this writing, checked directly — not asserted from a build plan. Where a platform's timeline is stated, that is a plan, not a completed fact.

Personal phone control

📋 Planned
TODAY: APP-BASED (e.g. LockedIn) APP Battery drain GPS tracked 24/7 NEMESIS: NETWORK-LEVEL (planned) No app installed School WiFi applies rules

The infrastructure to control personal phones on school WiFi — without requiring any app installation — is designed and planned. Unlike current solutions that require an app on every student's phone, Nemesis will enforce school rules at the network level, automatically. This is in development.

Reading and language learning

📋 Planned

Nemesis includes a built-in reading teacher powered by phonics — the evidence-based approach at the center of the Science of Reading movement.

Students get pronunciation support, phonics instruction, and vocabulary building integrated directly into every lesson. The same AI that teaches AI safety teaches reading.

For older students and ESL learners: a song lyrics library where students can bring their own songs or choose from Creative Commons licensed music. The AI teaches phonics, vocabulary, and cultural context through music.

Students can read aloud and receive real-time phonics feedback. The AI hears what they say, identifies the specific error, teaches the rule, and asks them to try again.

A language learning module lets any student practice a new language using the same phonics engine, the same reading library, and the same song library — with AI feedback in the target language.

All of this runs on the school's own hardware. Student voice data is never stored. Audio is processed in real time and discarded.
NEMESIS VOICE SYSTEM

Today: Lessons use browser speech synthesis. It works. It is a placeholder.

In development: A complete voice synthesis system written entirely by Nemesis Software. No third-party engines. No API keys. No vendor licenses. No external dependencies.

Our curriculum educators record this weekend. English phonemes, lesson content, connected speech.

The phoneme mapping engine uses those English recordings as the base for cross-language synthesis. Languages that share phonemes with English get real educator voices immediately. Language-specific sounds are added as native speaker sessions are recorded. Progressive improvement. No big-bang re-record required.

Demo: best effort to show the completed system on October 6. We show it when it sounds better than what it replaces. Not before.

Release: when it meets our quality standard. We tune it until it is right. Then we ship it.

What we own: every line of code. Every model weight. Every recording. No license that can change.
VOICE OPTIONS — the included tier is in development (see above); the two optional tiers below are roadmap, not built

Every Nemesis SL installation will ship with the Nemesis Voice — our educator-recorded voice, built this year, owned by us.

Schools have three paths, planned:

The Nemesis Voice (included) — in development, same status as above. Ships with every installation. No setup. No recording. No cost beyond the base license. Every school. Every student. The same trusted voice.

Language Pronunciation Packs — roadmap, design concept, not built. A school serving Arabic-speaking students wants authentic Arabic pronunciation — not just the Nemesis Voice approximating Arabic phonemes. The design: a native Arabic-speaking educator would record 30–45 minutes of language-specific sounds. The Nemesis Voice would handle everything the phoneme map already covers; the native recording would fill the gaps. Students would hear authentic pronunciation in the language they're learning.

Full School Voice — roadmap, design concept, not built; no school-side voice-training capability exists yet. A school wants their own identity. The design: a school's own educator records a complete script, and the appliance would train a custom voice model from it — entirely on the school's own hardware, never touching Nemesis Software's systems. Her voice. On their hardware. Theirs, if this ships as designed. We would never hear the recordings, and would never touch the model.

Schools could combine Full School Voice with Language Pronunciation Packs once both exist: their own voice, speaking every language, with authentic pronunciation.

Neither roadmap tier above is built today. The included Nemesis Voice tier is the only one currently in active development, and even that is not yet shipping.
READING LEVEL MEASUREMENT. Current implementation: Flesch-Kincaid Grade Level — an industry-standard formula, public domain, no licensing cost. It reports in grade-level terms every teacher and parent understands, plus a descriptive label (e.g. "Intermediate Reader") and an approximate Lexile reference band for context.

ROADMAP — Nemesis Reading Level (NRL), post-demo: a proprietary reading level metric owned outright by Nemesis, calibrated against Flesch-Kincaid and Lexile so districts can map it to whatever system they already use. No licensing fees. No dependency. No vendor terms that can change. Nemesis owns the metric — forever. The Flesch-Kincaid score is live today, on-demand per lesson in the teacher review tool. Automatic scoring for every lesson at publish time, and teacher/parent trend views over time, are next — not yet live. NRL itself is not built; it's the metric planned on top of this once FK is fully wired in.
SERVING EVERY LEARNER. Nemesis is built for the full range of learners in a modern classroom.

ESL students get a translation hover panel on every lesson screen — read the lesson in your home language alongside English. A student who speaks Spanish at home follows along in Spanish while learning to read in English. Nemesis bridges the gap. Today: lesson and vocabulary audio in Spanish, Arabic, Vietnamese and Mandarin as a comprehension aid. Spanish is the strongest — the synthesiser applies real Spanish pronunciation rules to the lesson text. The other three are accent-shaped rather than natively pronounced, and are honest about being a support tool rather than a substitute for a native speaker. Next: our own voice engine, recorded from our curriculum team and running entirely on the appliance. No cloud, no API, no per-word cost.

SPED students get audio narration so a student who struggles with reading can still access the curriculum, hints available on demand so a student who needs more support can request it without raising their hand, independent mode so they work at their own pace on their own timeline with no class-wide pressure, and a clean one-concept-per-screen design with no autoplay and no unexpected sounds.

IEP alignment: teachers assign specific lessons tied to IEP goals. Time on screen, quiz scores, and hint usage are tracked today and available as progress data.

Many ESL students also have IEPs. Nemesis serves both needs at once — home-language support and pacing/reading support — in one platform.

Nemesis doesn't have a separate ESL mode or a separate SPED mode. It serves every learner in the same classroom with the same platform — because that's how real classrooms work. Not yet built: reading-level-matched lesson assignment (Flesch-Kincaid isn't wired into lesson assignment yet), a teacher-facing view of in-progress student status with completion notifications, and home-language audio narration.

District management

📋 Planned

A district administrator sees all schools in their district from one dashboard.

This isn't an idea. It's a working system — and this is exactly what is and isn't built, checked against the actual project, not a wish list.

✅ Working today

  • Network security platform running (site blocking, threat detection, alert processing)
  • Agent heartbeat monitoring for enrolled school-owned devices
  • Over-the-air device updates — verified September 17, 2026
  • Device protection at home (enrolled school-owned devices)
  • AI learning assistant, active
  • Unlimited language translation, working (10 configured as shipped defaults)
  • 80+ lessons loaded, in review by the educator partner
  • Basic enrollment flow

🔨 Being built now (target: before the October demo)

  • Parent visibility portal
  • Student social platform
  • Emergency response system
  • Homework assistant with integrity monitoring
  • Bring your own lesson — teacher upload pipeline
  • Student learning profiles
  • Quiz generation (AI-assisted, reviewed by the educator partner)
  • Installing Nemesis on a school device is being built down to three steps: download the installer, double-click it, click Yes when Windows asks for permission. The installer is designed to handle everything else automatically — including installing any software it needs to work — so there's no IT training and no prerequisites to manage. Target: this week. Not yet verified end-to-end; today's install still needs a working zip file, not a single click.
  • Linux agent — core components exist, full parity with Windows not yet verified

📋 Planned, after funding

  • Personal phone control on school WiFi — network-level, no app required. This is the architecture, not yet built.
  • Full district management
  • Chrome browser extension
  • A research study with real schools
  • Collaboration with an educational psychologist

The live demo

Every device at the demo location connects to Nemesis running remotely via Tailscale — no local server, no special setup, the same architecture a real school deployment uses. The IT director, or investor, in the room watches in real time as their own devices appear in the dashboard; an unmanaged device attempting to reach a managed one gets blocked; a new device enrolls in about 30 seconds; the AI assistant responds to a real student question; and the cost tracker increments by a fraction of a cent for that call.

This is not a simulation. It is the product, running live, in the room.

Figures (30-second enrollment, per-call cost) are illustrative of a typical demo run, not independently re-measured for this document. As of this writing, this describes the demo as designed. The production dashboard has been running continuously since before today's firewall-rule and AI overage-pool work landed — a restart is required to bring that work online, and a full rehearsal against a freshly-restarted dashboard carrying today's changes has not yet happened.
Nothing above is overstated on purpose. If something looks unfinished, that's because it is — the plan is to be exactly this specific with the lawyer, too.

Today — COMPETITORS (average school)

$23,000 – $51,000 / year
5–6 different vendors
  • Student data stored at each vendor
  • Protection stops at the school door

Nemesis

$8,400–$21,000 one time, by school size
Everything included, one time$8,400–$21,000
  • Hardware, software, curriculum, translation, and narration — all included
  • Student data stays in the school
  • School owns it completely — no subscription, no renewal

Nemesis costs less than one year of what schools pay today for inferior, fragmented solutions — and there's no year two.

✅ Pricing decided, 2026-09-20 — a one-time purchase, not a subscription

Supersedes every earlier per-student and per-year figure in this document.

School sizePrice
Small (under 500 students)$8,400 — one time
Medium (500–1,500 students)$14,000 — one time
Large (1,500+ students)$21,000 — one time
District (5+ schools)Contact for custom pricing

Optional support plan

$1,200–$3,000/year, by school size. Covers platform updates, new curriculum additions, priority support, and the hardware replacement program.

Completely optional — the platform runs without it.

Nemesis is priced at roughly 70% of the average annual cost of comparable solutions — as a one-time purchase. The average school spends about $20,000 per year on the combination of tools Nemesis replaces (Section 02). For less than that single year's cost, Nemesis is owned outright — forever.

No subscription. No renewal fees. No vendor lock-in. No price increases. No access held hostage.

Year 1: you save 30%. Year 2: you save 100%. Year 3 onward: pure savings.

Cost comparison

Security tools$5,000–10,000/yr
Curriculum platform$12,000–25,000/yr
Translation$2,000–5,000/yr
TTS narration$1,000–3,000/yr
Competitors, total — yearly, forever$20,000–43,000/yr

Nemesis, once, forever: everything above for $8,400–21,000, one time.

Grant pathway

Nemesis works alongside schools to identify education-technology grants that cover the full purchase price. E-Rate, Title I, Title IV-A, and state technology grants frequently apply.

Many schools pay nothing out of pocket. We help you find out if yours qualifies.

Purchasing Nemesis SL

  • One-time purchase license.
  • Optional annual support plan ($1,200–$3,000/year by school size).
  • Purchase Orders accepted (Net-30).
  • Volume pricing for districts.

Contact support@nemesis-sw.com.

⚠ Not independently modeled this session: whether these tiers cover Nemesis's own hardware and support cost at these volumes, or what margin they leave. A real unit-economics pass is still owed before this is quoted to an investor as a margin claim rather than a customer price.

Every school starts where it's comfortable and goes as deep as it chooses. No all-or-nothing commitment, no district-wide decision required to get started.

Level 1 — Security only

✅ Available now

Blocks harmful content automatically. Protects enrolled school-owned devices at school and at home. No curriculum changes, no teacher training.

Who decides: IT director. Time to deploy: one afternoon. Cost: hardware + base license.

Level 2 — AI Safety curriculum

✅ Available now

Pre-built lessons on AI safety, internet safety, and digital citizenship — already built, translatable into any language the school configures, already tested. Students complete lessons before accessing the AI assistant.

Who decides: principal or IT director. Time to enable: ~10 minutes. Additional cost: included.

Level 3 — Build your own curriculum

📋 Vision, not yet built

A teacher describes a lesson on any subject; the AI builds it; the teacher reviews and publishes it. No district approval needed, no commitment beyond that one lesson.

Who decides: individual teacher. Depends entirely on the Curriculum Builder (section 08 below), which does not exist yet.

Level 4 — Subject integration

📋 Vision, not yet built

A department or school builds curriculum for a full subject, aligned to state standards, reviewed by their own teachers, replacing one subscription at a time.

Who decides: department head or curriculum director. Same Curriculum Builder dependency as Level 3, one tier up.

Level 5 — Full platform

📋 Vision, not yet built

Curriculum, assessment, AI tutoring, parent portal, and translation in one self-hosted system — Nemesis as the school's primary education platform.

Who decides: superintendent and school board. This is the Phase 3/4 vision in section 08, not a current option.

No school has to commit to Level 5 to get the benefits of Level 1. A school that starts with security and never builds a single lesson still saves money and protects students today. Nemesis is a tool, not a mandate — the depth of integration is entirely the school's choice.

Nemesis today is a working security platform with one curriculum built on top of it. The company's ambition is bigger — stated plainly here, phase by phase, so it's never confused with what exists right now.

What schools pay today, across a full EdTech stack

Separate vendors, per category, per year

Reading/ELA platform$15,000–40,000
Math platform$15,000–40,000
Science curriculum$10,000–30,000
Social Studies$10,000–25,000
Foreign Language$10,000–30,000
LMS$20,000–50,000
Assessment platform$10,000–25,000
AI tutoring$10,000–30,000
Translation services$10,000–20,000
Content filtering$5,000–15,000
Network security$10,000–30,000

Total today: $125,000–285,000 per school, per year, forever. These figures are the founder's own working estimates, not independently sourced this session — worth a real citation before quoting them to a grant board. The vision: hardware ($400-600, one time) plus a license, replacing all of it — eventually. Only Level 1 and 2 of that stack (network security, one curriculum) exist today; everything else is the roadmap below.

The market reframe this implies: not a ~$3B school-security niche, but the ~$89.49B global K-12 EdTech market (2023 figure, ~13.4% annual growth, operator-supplied and not independently verified this session) — every school, every subject, every grade, if the full vision is realized.

The four phases

  • Phase 1 — current, demo-ready: AI Safety curriculum, unlimited language translation, network security. The only phase with shipped, verified capability.
  • Phase 2 — grant funding: Curriculum Builder for any subject, IT/CS curriculum expansion, a research study, first 10 school pilots. Zero code exists yet.
  • Phase 3 — Series A: Full LMS features, multi-subject curriculum library, a curriculum marketplace, district management, an all-50-state standards database. Not scoped or designed.
  • Phase 4 — scale: International standards, university/community-college curriculum, corporate training, government/military education. Not scoped at all.

Attendance module — Phase 2, post-funding, target Q1 2027

The most critical real-time student data a school has is attendance: who is in the building right now. Nemesis SL Phase 2 adds a native attendance module that becomes the integration hub for emergency management, parent communication, and compliance reporting.

Solves immediately, once built: the gap between emergency management systems (like Raptor) and attendance systems — schools cannot get a real-time roster during fire drills or lockdowns because these systems don't connect today. Nemesis SL Attendance would connect them: one source of truth, real-time, already on the network, already trusted with security data.

Teacher dashboard: attendance, curriculum progress, and any security events in one view. Parent contact written from the same screen — no switching between systems, no re-entering information.

Class analytics: attendance patterns by class, curriculum completion by cohort, comparison across classes, intervention flags when patterns change.

District compliance: ADA reporting for state funding, federal compliance data, real-time district-wide headcount, emergency management at scale.

For schools that won't convert: custom connectors to existing attendance systems (PowerSchool, Skyward, Infinite Campus) available as a paid service. The integration works either way — the incentive to convert is the included price.

A connector is a maintenance liability by nature — a separate integration per vendor, breaking every time that vendor changes their API, with accountability split between two companies whenever something goes wrong. Nemesis doesn't compete with connectors by building a better one. It removes the need for one: attendance, security, and curriculum share the same database, the same real-time data, the same agent heartbeat already running on the device. Once a school is on that single system, a connector to a second, separate attendance product stops solving a problem the school still has.

Connectors are available. Most schools stop needing them by year two.

This is not a separate product. This is Nemesis SL becoming the infrastructure schools run on.

Zero code exists yet — same status as the rest of Phase 2. Named here in detail because the design is worked out, not because any of it is built.

Three-tier architecture — roadmap, post-demo

Nemesis is designed to scale to district deployments. Multi-school management is not built today — it's parked on the roadmap. Three deployment tiers share one codebase: a school buying Tier 2 today receives Tier 3 capability when it ships, at no additional license cost.

  • HOME (Tier 1): Parents connect to their child's school data from home via Tailscale. The data stays at the school. The home dashboard is a secure window — nothing is copied, nothing is stored remotely.
  • SATELLITE (Tier 2 — available today): One appliance per school. Complete security and education platform. Fully autonomous. Works with or without district connectivity.
  • PRIMARY (Tier 3): One district dashboard, receiving reports from each satellite school. Raw student data stays at each school — the primary sees aggregated reports only. District-wide policy override: push rules, curriculum standards, and emergency lockdowns to every school simultaneously. All communication over Tailscale VPN, encrypted end to end, always.
THE CORE PRINCIPLE: student data never moves. Ever.

Each school's Nemesis appliance holds that school's data. It never leaves the building. Not to the district. Not to the cloud. Not anywhere.

How district reporting would work: the district dashboard wouldn't store data from schools — it would query it, in place, on demand, with permission. "Show me all alerts across the district today" becomes the district node asking each school "what alerts did you have today?" Each school answers from its own data. The district sees a unified view. The data never moved.

FERPA by architecture: this wouldn't be a policy — it would be the design. Student data physically couldn't leave a school's appliance because the district node would have no database to put it in.

For parents with children at multiple schools: one parent login, one unified view. The district broker would query each school for that parent's permitted view, aggregate it, and return it — without storing it. Each school would control what parents can see. No school would see another school's data.

For home users: connect a home Nemesis dashboard to a child's school, if that school runs Nemesis, and see the child's permitted school activity from home. The home appliance would be a window — it stores nothing.

None of this is built. This is the design intent behind PRIMARY (Tier 3) above — federated query, not central storage — described precisely rather than left vague. The closest thing in the codebase is a roadmap stub explicitly marked "do not build yet" until district customers are actually in the pipeline.

Scaling — two different numbers, not one: the design principle is to size for the district number, not the school number (10 schools × 2,500 devices = a 25,000-device design target; a large district could reach 50,000+). That's separate from the 50,000-device benchmark quoted elsewhere in this document, which measures one appliance's database throughput (1,467 commits/second measured capacity) — not a multi-node district mesh, which hasn't been built or tested at any scale. Multi-district (spanning several independent districts) is further out still — tracked in the same roadmap stub as "v3+ / possible separate SKU," not yet scoped beyond that.

Privacy by architecture — the Nemesis ID system: this is design intent for the same unbuilt district tier above, not a shipped capability — most of what follows does not exist in the codebase today (one schema-only exception is noted below).

PRIVACY BY ARCHITECTURE — THE NEMESIS ID SYSTEM

Every student and parent would have a system-generated, opaque identifier — a random UUID that means nothing outside the system. A breach of the district node would reveal random UUIDs and school network addresses. It would not reveal student names, grades, or education data of any kind. FERPA compliance wouldn't be a policy — it would be the architecture.

NEMESIS_STUDENT_ID would be generated when a student enrolls, stored at the school only — no student name attached at any level above the school. NEMESIS_PARENT_ID would be generated when a parent registers, verified by school IT staff, linking to student IDs only after administrator verification — self-service linking would not be possible.

The multi-campus parent: a parent with children at different schools would have one NEMESIS_PARENT_ID. The district broker would match it to each school's student records — one login, all children, all schools, with no student data ever leaving any school building.

Most of this is still unbuilt. A parent_links database table now exists (schema only, live as of today, zero rows, no write path yet) — the first real building block for this design — but the IT-verification linking workflow, the parent portal, and the district broker are all still unbuilt. One real building block already ships too: a PARENT capability tier at the single-school level, governing real things like quarantine review under parental vicarious consent — but it's a role on an ordinary account, not the anonymized cross-school identity system described here.

Every answer below is checked against what the platform actually does today, not what's planned. Where something isn't built yet, it's listed separately as "Coming soon" rather than folded into a confident answer.

Q: Does this protect my child at school?
A: Yes. The Nemesis SL agent on managed devices blocks threats before they reach the device. Suspicious activity is flagged in real time and the IT administrator is alerted immediately.

Q: Who can see what my child does?
A: Only school staff authorized by your IT administrator — access to student data is restricted by role. Administrative changes to that access (a grant, a change, an override) are logged with a timestamp and the name of who made it.

Q: Does Nemesis Software see our school's data?
A: No. Nemesis SL is self-hosted on hardware the school owns. The Nemesis SL software does not transmit any data to Nemesis Software or any third party. Your data stays on your hardware.

Q: What if there's a school network security incident?
A: Nemesis SL detects threats in real time and alerts IT immediately. Every device on the network is visible, including ones that haven't been enrolled. An unrecognized device is automatically flagged for IT to review — quarantining it is an action IT takes, not something that happens without a person looking at it.

COMING SOON

✓ Parent portal — see your child's school activity from home
✓ Multi-campus view — children at different schools, one login
✓ Privacy-by-design ID system — student data anonymized at every level above the school

These are in active development and are targeted to ship before the first district deployment.

The Nemesis data volume is encrypted at rest.

Nemesis protects student data with hardware-backed encryption. Student work is reviewed by teachers, not algorithms or a technology company — the school owns the hardware, the school owns the data.

✅ AVAILABLE TODAY: TPM-backed volume encryption (LUKS2 + TPM2, live as of 2026-09-21).

Nemesis protects student data with hardware-backed encryption:
  • The Nemesis data volume is encrypted using LUKS2 with AES-256 encryption.
  • The encryption key is sealed to the appliance's TPM 2.0 chip — the same hardware that verifies every agent binary on the network. Physical disk removal cannot decrypt the data without the original TPM.
  • Normal restarts are designed to be fully automatic — no passphrase, no manual step.
  • A break-glass recovery key is stored separately for disaster scenarios.
  • Backup copies are GPG-encrypted before writing to removable media.

What this protects: disk theft or loss; appliance RMA or disposal; lost or stolen backup media.

Honest boundary: this covers the Nemesis data volume. System logs and configuration files are outside this boundary — documented honestly rather than obscured. ✅ Live as of 2026-09-21 — running on the production appliance today.

For districts with multiple schools: data travels between school appliances and the district dashboard exclusively over Tailscale VPN — encrypted end to end, never touching the public internet.

AI-assisted features

Hint comprehension, lesson translation, and the teaching assistant process content via Anthropic's API.

What is sent: lesson text and anonymized student responses.
What is NOT sent: student names, IDs, grades, or any identifying information.

API calls are governed by Anthropic's data processing agreement. Under current terms, API inputs are not used to train Anthropic's models. Schools should review Anthropic's API privacy policy for their own compliance requirements.

Transparency note. The Nemesis teaching assistant sends student questions to Anthropic's API verbatim. No student name, ID, or identifying information is included in the request. Schools should review this against their FERPA obligations and Anthropic's API data processing terms.

AI feature controls

AI features can be disabled globally today. Per-feature controls (Lesson Assistant, Hint Comprehension Check, Lesson Translation, Auto-Marker Placement, each independently) are in active development and will be available before release.

AI usage — always on for students

✅ Working

Nemesis uses a three-pool budget system so students are never refused a hint or lesson response because of a budget limit.

  • Base pool — 2,000 calls/hour, default. Every AI request served instantly.
  • Overage pool — 200 calls/hour, default. When the base pool is exhausted, AI keeps serving students from the overage pool. Students notice nothing; IT is alerted immediately.
  • Hard stop. Only when both pools are exhausted do students see: "Nemesis is taking a short rest. Try again in a few minutes!" IT gets an urgent alert and can add budget instantly from the dashboard.
At a 3,000-student school, expected peak demand is roughly 1,600 calls/hour — comfortably inside the 2,000/hour base pool default. Both pool sizes and every alert threshold are IT-configurable dashboard settings, not fixed in code.
The base/overage split, the settings and the three status states above are live and tested today. Alert checkboxes are real, persisted settings, but do not yet send email/SMS to IT — that delivery step is not wired yet, and this document says so rather than implying it.

AI usage intelligence

✅ Working

Nemesis tracks every overage event: which AI feature triggered it, time of day and day of week, how many calls went over the limit, and its estimated cost and duration.

Patterns are surfaced automatically from that history — peak usage hours and days, the most common trigger feature, average overage duration, and monthly overage cost — so IT directors can tune the base limit from real data instead of a guess.

Illustrative example of what that data supports: "Your peak AI demand is 11:30 AM–12:30 PM on weekdays. Consider raising the base limit to 2,500/hour during that window. Estimated extra cost: $0.43/day."
The underlying tracking — 30-day overage history, peak-hour detection, monthly cost totals — is live and tested. The recommendation shown above illustrates what that data makes possible; it is not yet auto-generated copy in the dashboard today.

Enterprise Readiness Roadmap

Nemesis is built to enterprise standards from day one. Here is our honest assessment of where we are and what we are actively building:

✅ Available today

  • Single-school deployment
  • Device management (design target: 2,500+ per school)
  • Role-based access control
  • Audit logging
  • OTA agent management
  • AI Safety curriculum
  • AI teaching assistant
  • Multi-language translation
  • Global AI spending cap
  • TPM-backed volume encryption (LUKS2 + TPM2, live as of 2026-09-21)

🔨 In active development

  • Per-feature AI controls
  • Translation approval workflow
  • Job engine (load balancing)
  • Per-feature spending controls
  • Production web server (nginx + gunicorn)

📋 Pre-release (before first sale)

  • FERPA compliance documentation
  • Multi-school data isolation
  • District RBAC scope
  • Database query optimization for 50,000+ devices

📋 District scale

  • Primary dashboard (Tier 3)
  • Cross-school reporting
  • District-wide policy override

Schools that deploy Nemesis today receive all future capabilities as they ship — at no additional license cost.

Device segmentation

✅ Live today

Unknown devices are automatically placed in a restricted network segment. They cannot reach school resources through the guaranteed enforcement path — that specific guarantee is what the Visitor Network Policy below adds. Full visitor policy controls are on the roadmap.

What's confirmed live today: a device without an enrollment tag is placed into a distinct, restrictive DHCP scope. What's on the roadmap: the linked firewall/routing enforcement that formally guarantees a segmented device can't reach internal resources — see Visitor Network Policy, below.

Network architecture roadmap

📋 Planned
  • Zero-trust network — four tiers. Every device is classified and gated automatically; nothing gets default access.
    • Tier 1 — Agent devices (Tailscale). Full Nemesis agent, verified identity, full platform access.
    • Tier 2 — Known non-agent devices. IT-registered by MAC address — IoT, printers, cameras. Device-type rule templates (PRINTER, CAMERA, CLASSROOM_AV, STAFF_PERSONAL). Cannot reach school resources or other devices.
    • Tier 3 — Unknown devices. No agent, not on the approved list — fully blocked by default. IT grants specific access; every grant is logged, with an expiry.
    • Tier 4 — Quarantine. Triggered by an alert or suspicious behavior. Complete isolation — zero internet, zero LAN — until an IT director manually releases the device.
    Each tier has its own rule set. Unknown devices get nothing until IT deliberately opens access. Implementation: post-demo.

This is a genuine differentiator, not a slogan: every competitor sends student data to their own servers. Nemesis doesn't — it's self-hosted, with hardware-backed encryption live today and granular AI controls in active development.

Building all of this in one product requires expertise across network security, artificial intelligence, education technology, and translation — all at the same time.

Large companies build one piece well and charge a lot for it. They have no incentive to combine everything into one affordable, self-hosted package.

Small developers rarely have the security expertise to build the network protection layer correctly.

Nemesis was built by someone with experience across all of these areas, motivated by one question: why should only wealthy schools be able to afford to protect their students?

We believe Nemesis improves outcomes. We need funding to prove it.

  1. Do students who earn AI access through curriculum completion use AI more responsibly than students with unrestricted access?
  2. Do students whose AI assistant adapts its pace and depth to individual performance show better outcomes than students with a one-size-fits-all assistant?
  3. Does consistent protection — at school and at home — produce better safety outcomes than protection that stops at the school door?
  4. Does network-level phone control reduce classroom disruption more than app-based approaches?When built — this is a study nobody can currently run, because no network-level solution exists yet.

These are answerable questions. No one has answered them yet, because no one has had a platform that could ask them. Until now.

P

Paul Lozelle — independent developer

Paul is an independent software developer based in Houston, Texas. He built Nemesis because he believes every school — regardless of budget — deserves the same protection as the wealthiest districts.

A

Angela Campbell-Lozelle — educator partner

Certified ELA and ESL Teacher and Instructional Coach, M.Ed., Texas A&M University 2026. She has tested and reviewed the curriculum platform throughout development, and her feedback has shaped every education feature in the system.

Nemesis is not venture-funded. It was built by one person, with one goal: make enterprise-level school protection accessible to every school in America.

Why one system matters.

Our founder spent years at ADP, watching the difference between businesses running one integrated payroll system and businesses managing six vendors who pointed fingers when Friday's payroll failed. The businesses with one system called one number, got one answer, and were back to business in hours. The businesses with six vendors spent days in conference calls while employees waited for paychecks.

K-12 schools face the same choice today: Skyward for attendance, Raptor for emergencies, Fortinet for security, an app like ClassDojo for parent communication, a curriculum vendor for digital literacy, a content filter for acceptable use. Six vendors, six support contracts, six systems that don't talk to each other — and when they don't, as this document's own Attendance section (08) describes for Raptor and attendance systems on fire-drill day, there's nobody who owns the outcome.

Nemesis SL is built on the same principle that made ADP work: one system, one vendor, one call when something breaks. Not because it's the only option — because it's the option where every piece was designed to work with every other piece, by the same team, from the same codebase, on hardware the school owns.

When something breaks: call us. We fix it. You get back to protecting students.

135 days.
357,186 lines of code.
One developer.
Zero outside funding.

The platform you are reading about was built by one person.

Paul Lozelle designed and architected every system in Nemesis — the security platform, the education center, the AI assistant, the data-driven teaching engine. Every product decision, every standard, every rejection of work that didn't meet the bar. That was Paul.

Every line of code was written by Claude AI. Not assisted by AI. Not reviewed by AI. Written by AI — under continuous human direction, judgment, and quality control. 15,000+ lines of Python, JavaScript, and SQL. A Windows agent with TPM-backed attestation. A quiz system with server-side scoring. 57 lessons across four grade bands. A unified AI assistant that works across every surface of the platform.

The curriculum was designed by Angela Campbell-Lozelle — a Certified ELA and ESL Teacher and Instructional Coach, M.Ed., Texas A&M University 2026. The research basis, the lesson structure, the age-appropriate content decisions for each grade band — that is her expertise. Claude AI built 57 lessons to her standard. Every lesson was reviewed against her design rules. Her judgment was the quality gate.

This is not a story about AI replacing human expertise. It is a demonstration of what happens when human expertise and AI capability work together correctly.

Nemesis teaches students that AI is a tool that amplifies human capability — not a replacement for human thinking, judgment, or creativity. Nemesis itself is the proof of that principle.

The platform you are evaluating was built exactly the way it teaches. The method and the message are the same thing.

That is intentional.

Students who complete the Nemesis curriculum read this same statement before their first lesson — in language appropriate for their age.

They begin their AI education already experiencing the principle they are about to learn.

Product milestone: October 6, 2026. Investor meeting: October 2026 — no specific date set. These are two separate events. October 6 is an internal readiness target — the point everything in this document is being built toward, described below and throughout. It is not the date an investor is scheduled to see it.

Nemesis's current build sprint — one developer and three AI sessions working toward the October 6 demo — runs eleven days. (The platform itself started earlier than that; this is the sprint that carried it from mid-build to demo-ready.)

Every decision about what to build first was a prioritization decision. We built what students need to learn. We built what teachers need to teach. We built what IT directors need to trust the platform. We built what parents need to understand their child's safety.

We did not build district-level reporting, because there is no district yet. We did not build fleet-scale validation, because there is no fleet yet. We did not build full malware corpus validation, because there is no corpus budget yet.

Those are not omissions. They are correct sequencing: build what proves the concept, validate with real users, scale with real funding.

Everything that is here works. Everything that is not here has a plan, a timeline, and a funding requirement. That is not a weakness. That is how good software gets built.

Takes 2 minutes. Nothing here is stored on our end until you hit send in your own email — see the note below.

(Don't look back — just write what you remember.)
(optional)
(optional)
(optional — only if you'd like a follow-up)

Please answer the required questions (marked without "optional") before submitting.

This opens a pre-filled email in your own email app, addressed to Paul — nothing is sent until you hit send there. There's no server collecting responses automatically.

Want the full technical details and architecture documentation?
Request NDA-protected access.

Link copied