Skip to content

Knowing where your child is is only part of safety.

MTFDX Safe focuses more on “who is authorized to pick up, who is currently responsible, whether the handover is complete, and who handles the next step when something goes wrong.”

Every pickup should answer four questions.

01

Who can pick up?

02

Who is responsible now?

03

Is the handover complete?

04

Who handles exceptions?

A Trusted Adult does not mean permanent permission.

Grandparents, teachers, coaches, temporary drivers and others can receive the minimum necessary permission based on the child, the scenario, and the time window.

  • Time-window permissions
  • Guardian approval
  • Valid only when needed

Responsibility changes only after both sides confirm.

If the receiver does not arrive, verification fails, or the child does not appear, the original responsible party is kept and the exception flow begins.

  1. Plan
  2. Authorize
  3. Verify
  4. Handover
  5. Receive
  6. Responsibility

Family view (confirmed together)

Haru TanakaConfirmed
15:30 scheduled pickup
CancelConfirm

Institution view (confirmed together)

Haru TanakaMatch
Verify receiver by QR / PIN
HoldVerify

Responsibility moves only after both sides confirm.

Different devices, unified into one safety language.

Sources such as GPS, access control, school buses, and manual confirmation are all converted into a unified Safety Event, and upstream flows do not depend on device brands.

  • GPS / access / bus
  • Human-confirmed input
  • Normalised to one event

Confirm first, then escalate.

The system does not label every delay as danger; emergency response starts only after high risk is confirmed.

  • Normal: quiet
  • Needs confirmation: verify first
  • Emergency: only after confirmation

Safety flows cannot assume the network is always available.

Organizations can cache the necessary roster and authorization summary for the day; after the network recovers, records are written back and marked offline_origin.

Offline, today's essentials stay available.

Organizations can cache the necessary roster and authorization summary for the day; after the network recovers, records are written back and marked offline_origin.

  • Cache only today's roster and consents
  • Re-sync on reconnect, tagged offline_origin

Start verifying with one real handover.