Security & Trust Center

Everything your IT, security, and procurement teams need to evaluate PRISM. Encrypted in transit and at rest. Student data is never sold and never used to train AI models.

Compliance & certifications

FERPA & COPPA

Compliant

PRISM operates as a "school official" under FERPA and complies with COPPA. We process student data only to provide the service to the district and never for advertising. See our Privacy Policy.

SOC 2 Type II

In progress

Our controls are mapped to the SOC 2 Trust Services Criteria. A current status letter and security overview are available under NDA — request from our team.

Accessibility (WCAG 2.2 AA)

Conformant

PRISM is built to WCAG 2.2 AA. See our Accessibility statement; a full VPAT is available on request.

State privacy laws

Supported

We honor state student-data-privacy statutes (e.g., California SOPIPA) and will sign state- and district-specific addenda. Tell us your state's requirements.

Student data privacy agreements

Districts shouldn't have to take security on faith. PRISM will enter into the data privacy agreement your district or state requires:

  • National Data Privacy Agreement (NDPA / SDPC): we will execute the Student Data Privacy Consortium NDPA and join your state's alliance page.
  • District or state DPAs: we review and sign district- and state-specific agreements and exhibits.
  • Data Processing Addendum (DPA): available for districts that require one as part of the master agreement.

To start a DPA, email help@prismschools.com with your district name and the agreement template you use.

Subprocessors

PRISM relies on a short list of vetted subprocessors. AI providers are contractually bound: student data is never used to train their models.

Subprocessor Purpose Data handled Region
Amazon Web Services (AWS) Application hosting, database (RDS), file storage (S3), authentication (Cognito), email (SES), secrets (Systems Manager) All application & student data, encrypted at rest United States
Anthropic AI generation (Claude) — summaries, meeting briefs, intervention recommendations Prompt content only; not used for model training United States
Google AI generation (Gemini); optional Workspace integrations (Classroom, Drive, Sheets, Calendar) when a district connects them Prompt content / district-authorized Workspace data; not used for model training United States
OpenAI AI generation (fallback provider) Prompt content only; not used for model training United States

We notify customers of material changes to this list. Optional integrations (Clever, OneRoster, Canvas, Google Workspace) only exchange data after a district connects them.

Data lifecycle & residency

  • What we store: rosters, attendance, grades, observations, intervention plans, screener results, and the AI-generated summaries built from them.
  • Reads from your SIS, never replaces it: PRISM syncs from your system of record and writes to its own layer; it is not the district's system of record.
  • Residency: data is hosted in the United States on AWS, encrypted in transit (TLS) and at rest.
  • Retention & deletion: data is retained for the life of the agreement and deleted or returned on request at termination, per your DPA.

Access control & authentication

  • Single sign-on: authentication via AWS Cognito, including Google federated sign-in.
  • Role-based access control: System, District, School Admin, Interventionist, SPED Coordinator, and Teacher roles, each scoped to the data they need.
  • School scoping: school-level users only see their assigned schools.
  • Audit trail: security-relevant actions are recorded in an internal audit log.

How PRISM uses AI

  • No training on student data. Our AI providers are contractually prohibited from using your data to train their models.
  • Never sold. Student data is never sold or shared for advertising.
  • Grounded, reviewable output. AI summaries, briefs, and recommendations are generated from the district's own data and are always reviewable by educators before action.
  • Human in the loop. PRISM supports decisions; it does not make placement or eligibility decisions on its own.

Procurement pack

Documents your evaluation team may need. Items marked "under NDA" are shared after a mutual NDA.

Need a security & compliance review?

We'll walk your IT and procurement teams through architecture, data flows, and agreements, and answer your security questionnaire.

Request a security review