C
Coquina DBCPS OSP / EOCO
All· All offices · Cross-functional
Dashboard
TriageEmail InboxAll ReportsCasesDecisionsManual ReportTemplatesBulk Case Export
ComplianceSpecial HandlingAudit Log
SchoolsDirectory
ReportsTrends
Support & Training

Trust Center

SOC 2 Type II

Certified · 2025–2026 cycle

Annual audit by independent CPA firm. Report available under NDA.

FERPA / Title IX

Compliant

Field-level permission controls enforce least-privilege access to PII.

HIPAA

Compliant · BAA available

Business Associate Agreement available for PHI workflows.

SOPPA (Illinois)

Annual filing on record

Student Online Personal Protection Act vendor data attestation.

ISO 27001:2022

Certified · re-audited annually

Information Security Management System with 114 controls.

Encryption

AES-256 at rest · TLS 1.3 in transit

Customer-managed keys via AWS KMS. Strong cipher suites only.

Status Page

All systems operationalView incident & release history →

Data Residency

US-only · AWS us-east-1 + us-west-2

No data leaves the United States. Active-active multi-region.

Security Contact

Vulnerability reports: security@coquinadb.example

PGP key available on request

Service Level Objectives

Live targets for the contractual SLA

MetricTargetCurrent
Uptime (rolling 12-month)≥ 99.95%99.97%
Recovery Point Objective (RPO)≤ 1 hourContinuous replication
Recovery Time Objective (RTO)≤ 4 hoursValidated quarterly
Mean Time to Notify (security incident)≤ 24 hours< 4 hours
Avg case page load≤ 2,000 ms720 ms

Compliance Controls Matrix

Mapped to SOC 2, HIPAA, FERPA, SOPPA, Title IX, ISO 27001, NIST 800-53

Request evidence packet
FrameworkControlStatusEvidence
SOC 2 Type IICC6.1 — Logical access controls ContinuousPersona-aware RBAC + MFA enforced; SAML SSO with auth-event log
SOC 2 Type IICC7.2 — Anomaly detection ContinuousImmutable 7-year audit trail across 35+ event types
HIPAA164.312(a) — Access controls In PlacePHI fields gated by least-privilege role + cell-level audit on view
HIPAA164.312(b) — Audit controls Continuous10,000+ events/month; tamper-evident hash chain; 7-year retention
SOPPA (IL 105 ILCS 85)Vendor data-handling attestation AnnualAnnual SOPPA filing with Chicago Public Schools and ISBE
FERPA34 C.F.R. § 99.31 — Disclosure limits In PlaceDocument share links scoped to single recipient + expiry; share revocation logged
Title IX34 C.F.R. § 106.45 — Grievance procedures In Place9 verbatim case-team roles, stage-gated transitions, COI declarations
ISO 27001:2022A.5.30 — ICT readiness for BC AnnualActive-active multi-region (us-east-1 + us-west-2); RPO 1h / RTO 4h
NIST SP 800-53AU-9 — Protection of audit information ContinuousAppend-only audit store; no edit/delete UI surface anywhere