Legal

Security and Sub-processors

Effective July 27, 2026 ยท Last reviewed July 27, 2026

This page exists so your information security office can complete its review without a call. If something you need is missing, ask and we will add it here rather than answer privately, so the next institution benefits too.

For a formal vendor assessment, start at the Trust Center: our HECVAT 4 response, VPAT 2.5 conformance report and a signature-ready DPA and FERPA addendum are all published in full.

Architecture and isolation

The Service is multi-tenant. Every record carries a tenant identifier and every query is scoped by it at the framework level rather than by developer discipline, so an unscoped query fails rather than silently returning another institution's data. Cross-tenant isolation is covered by automated tests that run on every change.

Institutions are separated logically, not physically. If your policy requires a single- tenant deployment, tell us before you onboard.

Encryption

  • In transit: TLS 1.2 or higher for all connections. HTTP is redirected to HTTPS.
  • At rest: full-disk encryption on all storage, with sensitive fields additionally

encrypted at the application layer.

  • Backups: encrypted, with access restricted to the same least-privilege set.

Access control

  • Role-based access within each institution, controlled by your administrators.
  • Optional campus single sign-on via SAML 2.0 or OpenID Connect, supporting Shibboleth,

InCommon, Azure AD and Google Workspace. SSO can be set to required.

  • Our own staff access to production is least-privilege, individually attributed,

requires multi-factor authentication, and is logged.

  • Rater links are single-use, expiring, cryptographically random and bound to one

student and one experience. A rater link never grants a session on any account.

Audit logging

Authentication events, data exports, administrative actions and record modifications are written to an append-only audit log with actor, timestamp and affected record. Institutional administrators can read their own institution's log. This exists partly so that a FERPA access review can be answered with evidence rather than assertion.

Sub-processors

Sub-processorPurposeDataLocation
Liquid WebApplication and database hostingAll service dataUnited States
CloudflareDNS, TLS termination, DDoS protectionTraffic metadataUnited States
Mailgun (Sinch)Transactional emailRecipient address, message contentUnited States
AnthropicAI-generated development narrativesCompetency scores, limited contextUnited States

All service data is stored in the United States. We will give institutional administrators notice before adding a sub-processor that would process personal data, so you have the opportunity to object.

Our agreement with our AI provider prohibits training on content submitted through the API. Student narratives are not used to improve any third-party model.

Vulnerability reporting

We welcome reports and will not pursue legal action against good-faith research that respects the following: do not access, modify or exfiltrate data belonging to anyone other than a test account you control; do not degrade the Service; do not run automated scanning that generates significant load; and give us a reasonable period to remediate before disclosing.

[email protected]

We aim to acknowledge within two business days. We do not currently operate a paid bounty, and we will credit you publicly if you would like that.

Incident response

If a security incident affects your data, we will notify your institutional administrators without undue delay and in any event within 72 hours of confirming it, with what we know, what we are doing, and what we recommend you do. We will follow up with a written account once the investigation closes.

Because your institution is the controller of its student records, any notification to students or to regulators is your decision. We will give you what you need to make it.

What we do not yet have

Stated plainly, because a security questionnaire will ask:

  • No SOC 2 Type II report. A free product does not currently justify the audit cost. If

your procurement process makes this a hard requirement, tell us; enough demand changes the calculation.

  • No penetration test by an independent third party yet. Planned before the platform

launch, and the summary letter will be published here.

  • No formal ISO 27001 certification.
  • No cyber liability insurance. We cannot provide a certificate of insurance naming

your institution as an additional insured. If your contract requires one, we cannot meet that requirement today.

  • No separately staffed information security department. Security responsibilities sit

with the engineering lead who operates the platform.

  • No TX-RAMP or StateRAMP authorization.

We would rather you know that up front than discover it three weeks into a review. Any one of these may be disqualifying for your institution, and that is a legitimate call to make from a public page in ten minutes rather than in week three.