Enterprise-Grade Security
Your data stays yours. We build AI solutions with security and privacy at the coreβdesigned for education institutions that trust us with their most sensitive information.
Compliance & Certifications
Built with education-specific privacy regulations in mind from day one
FERPA
Family Educational Rights and Privacy Act
Student data privacy protections for educational records
COPPA
Children's Online Privacy Protection Act
Protection for children under 13 years of age
GDPR
General Data Protection Regulation
EU data protection and privacy standards
Security Overview
Documented controls, no third-party certification yet
We do not hold a SOC 2 report. Our controls are documented in a security overview available on request.
WCAG 2.1 AA
Web Content Accessibility Guidelines
Digital accessibility compliance standards
CCPA
California Consumer Privacy Act
California privacy rights compliance
Data Security Practices
Industry-leading security practices protecting your educational data
Encryption at Rest & In Transit
All traffic is encrypted in transit with TLS 1.2/1.3. Database-level encryption at rest is on our roadmap; ask us for the current status before relying on it.
Access Control
Production access is limited to named Evelyn Learning engineers. Admin dashboards require Google sign-in restricted to an allowlist of staff accounts.
Data Isolation
Each white-label brand runs on its own database. Partner API access uses per-partner secrets that can be rotated on request.
Audit Logging
Application and session logs are retained for troubleshooting and quality review. Formal audit trails of data access are on our roadmap.
Security Testing
Dependencies are scanned for known vulnerabilities. No third-party penetration test has been completed yet; one is planned before our first district contract.
Secure Development
Code review before release, typed codebase with automated test suites, scripted deployments verified after each release.
Infrastructure Security
Enterprise-grade infrastructure built for reliability and security
Infrastructure
- Hosted on dedicated virtual servers running Ubuntu LTS
- HTTPS everywhere with TLS 1.2/1.3 and automatically renewed certificates
- Signed, short-lived session tokens for embedded tutoring sessions
- Rate limits and daily quotas per partner and per endpoint
Monitoring & Response
- Process supervision with automatic restart and health checks
- Session-level telemetry reviewed for quality and abuse
- Partners notified within 72 hours of a confirmed security incident
- Named engineering owner for incident response
Backup & Recovery
- Scripted, repeatable deployments from version-controlled releases
- Session data exportable to partners on request
- Automated off-site database backups are being put in place; ask us for current status
- Documented rollback procedure for every release
Privacy Commitments
Clear promises about how we handle your data
Your Data Stays Yours
You retain full ownership of all data you provide to us. We process your data only to provide our services.
No AI Training on Your Data
We never use your content or student data to train AI models. Your data is used solely to deliver your requested services.
Data Minimization
We only collect data necessary to provide our services. No excessive data collection or retention.
Right to Deletion
Request deletion of your data at any time. We process deletion requests within 30 days.
Transparent Processing
Clear documentation of how we use your data. No hidden purposes or surprise data sharing.
Student Privacy First
Educator-designed with student privacy as a foundational principle. Extra protections for minors.
Vendor & AI Provider Security
We carefully vet our technology partners to ensure they meet our security standards
Anthropic (Claude)
No training on API data. Prompts not stored beyond request processing.
OpenAI
API data not used for training. Zero data retention available.
Cartesia (speech)
Processes tutor speech and student audio for the session only. Full sub-processor list available on request.
Questions About Security?
Our team is happy to discuss your specific security requirements, provide additional documentation, or walk through our security practices in detail.