Trust Center
SOC 2 Type II
Certified · 2025–2026 cycleAnnual audit by independent CPA firm. Report available under NDA.
FERPA / Title IX
CompliantField-level permission controls enforce least-privilege access to PII.
HIPAA
Compliant · BAA availableBusiness Associate Agreement available for PHI workflows.
SOPPA (Illinois)
Annual filing on recordStudent Online Personal Protection Act vendor data attestation.
ISO 27001:2022
Certified · re-audited annuallyInformation Security Management System with 114 controls.
Encryption
AES-256 at rest · TLS 1.3 in transitCustomer-managed keys via AWS KMS. Strong cipher suites only.
Data Residency
US-only · AWS us-east-1 + us-west-2No data leaves the United States. Active-active multi-region.
Service Level Objectives
Live targets for the contractual SLA
| Metric | Target | Current |
|---|---|---|
| Uptime (rolling 12-month) | ≥ 99.95% | 99.97% |
| Recovery Point Objective (RPO) | ≤ 1 hour | Continuous replication |
| Recovery Time Objective (RTO) | ≤ 4 hours | Validated quarterly |
| Mean Time to Notify (security incident) | ≤ 24 hours | < 4 hours |
| Avg case page load | ≤ 2,000 ms | 720 ms |
Compliance Controls Matrix
Mapped to SOC 2, HIPAA, FERPA, SOPPA, Title IX, ISO 27001, NIST 800-53
| Framework | Control | Status | Evidence |
|---|---|---|---|
| SOC 2 Type II | CC6.1 — Logical access controls | Continuous | Persona-aware RBAC + MFA enforced; SAML SSO with auth-event log |
| SOC 2 Type II | CC7.2 — Anomaly detection | Continuous | Immutable 7-year audit trail across 35+ event types |
| HIPAA | 164.312(a) — Access controls | In Place | PHI fields gated by least-privilege role + cell-level audit on view |
| HIPAA | 164.312(b) — Audit controls | Continuous | 10,000+ events/month; tamper-evident hash chain; 7-year retention |
| SOPPA (IL 105 ILCS 85) | Vendor data-handling attestation | Annual | Annual SOPPA filing with Chicago Public Schools and ISBE |
| FERPA | 34 C.F.R. § 99.31 — Disclosure limits | In Place | Document share links scoped to single recipient + expiry; share revocation logged |
| Title IX | 34 C.F.R. § 106.45 — Grievance procedures | In Place | 9 verbatim case-team roles, stage-gated transitions, COI declarations |
| ISO 27001:2022 | A.5.30 — ICT readiness for BC | Annual | Active-active multi-region (us-east-1 + us-west-2); RPO 1h / RTO 4h |
| NIST SP 800-53 | AU-9 — Protection of audit information | Continuous | Append-only audit store; no edit/delete UI surface anywhere |