Trust Center
Last updated: 26 July 2026
Current status
- SOC 2: Not yet audited. Control library and evidence program in progress (see
docs/compliance/). - ISO/IEC 27001: Not yet certified. Statement of Applicability draft mapped to the same controls.
- GDPR: Processor model + DPA template + DSAR export tooling available.
- FERPA / SOPIPA: Technical access controls, no-ads commitments, school deletion/export workflows, guardian linkage.
Documents
- Privacy Policy
- Terms of Service
- Subprocessors
- Security overview
- Customer DPA template:
docs/legal/DPA.md - FERPA / SOPIPA addendum:
docs/legal/FERPA-SOPIPA-ADDENDUM.md
Product safeguards
- Multi-tenant isolation with PostgreSQL Row Level Security
- Role-based permissions (including parent/guardian links)
- Append-only audit trail for sensitive mutations and share views
- Expiring report-card share links with rotate/revoke
- Security headers (CSP, HSTS in production, frame denial)
Request under NDA
SOC 2 reports and detailed questionnaires will be shared with schools under NDA once audits complete. Contact us via the marketing demo channel.