Trust Center

Last updated: 26 July 2026

Current status

  • SOC 2: Not yet audited. Control library and evidence program in progress (see docs/compliance/).
  • ISO/IEC 27001: Not yet certified. Statement of Applicability draft mapped to the same controls.
  • GDPR: Processor model + DPA template + DSAR export tooling available.
  • FERPA / SOPIPA: Technical access controls, no-ads commitments, school deletion/export workflows, guardian linkage.

Documents

Product safeguards

  • Multi-tenant isolation with PostgreSQL Row Level Security
  • Role-based permissions (including parent/guardian links)
  • Append-only audit trail for sensitive mutations and share views
  • Expiring report-card share links with rotate/revoke
  • Security headers (CSP, HSTS in production, frame denial)

Request under NDA

SOC 2 reports and detailed questionnaires will be shared with schools under NDA once audits complete. Contact us via the marketing demo channel.