Home/Security & trust

Student data, held to the standard universities require.

Student records are the most sensitive data a school hands over. We treat them that way from day one, and we can prove it. CampusAI is SOC 2 Type 1, FERPA-aligned, and built so a school always stays in control of its own data.

SOC 2 Type 1
Achieved · continuously monitored in Vanta
FERPA-aligned
Education-record handling by design
WCAG 2.2 AA
Accessible · Section 508
The audit

What our SOC 2 Type 1 report actually means.

An independent audit of how we protect data

SOC 2 is an in-depth external audit, defined by the American Institute of CPAs (AICPA), that examines how a company secures the information it handles. An independent auditor reviews our controls, policies, and practices against five trust principles.

SecurityAvailabilityProcessing integrityConfidentialityPrivacy

What Type 1 covers, and what comes next

A Type 1 report confirms our security controls are properly designed and in place at a point in time. It is the recognized baseline schools look for before trusting a vendor with student data.

We keep those controls under continuous monitoring in Vanta, and SOC 2 Type 2, which validates that the controls operate effectively over time, is on our roadmap.

How we protect student data

The controls behind the certificate.

The audit checks that these are real. Here is what they mean for a school and its students in plain terms.

Encrypted in transit and at rest

Data is protected everywhere it moves and everywhere it lives, using industry-standard encryption end to end.

Tenant isolation

Every school's data is walled off from every other tenant. One institution can never see another's students.

Single sign-on

Students and staff log in through your existing identity provider, so access follows the rules your school already runs.

Audit logging

Every privileged action is recorded and reviewable, so access to sensitive data is always traceable.

Least-privilege access

People and services only reach the data their role requires, with hardware-key MFA on the most sensitive accounts.

Continuous monitoring

Controls are tracked and re-checked continuously in Vanta, not proven once and forgotten after the audit.

FERPA and student privacy

A career platform only works if students trust it with real information. So privacy is built into the product, not bolted on. Education records are handled to FERPA requirements, and the analytics we give schools never expose an individual student.

Cohort-level analytics only

Staff see aggregates and trends, never an individual student's record without a legitimate, logged reason.

Small cohorts suppressed

Aggregates below a minimum group size are hidden, so no student can be re-identified from the numbers.

The data stays the school's

Export or delete on request. The institution owns its data, and account deletion is a real, working path.

Never sold, never used to train outside models

Student data is used to serve that student and that school. It is not sold, and it is not used to train third-party models.

Sub-processors

The vetted infrastructure providers we rely on to run CampusAI. Each is held to the same data-protection standard.

  • Amazon Web Services Hosting & storage
  • Google Cloud AI & compute
  • Google Workspace Internal operations
  • Slack Internal collaboration

Reviewing CampusAI for your school?

We'll walk your security and IT teams through our controls and share the documentation your review needs.