Skip to content
Security & Compliance

Built for student data.

Schools trust Clearlinks with millions of documents containing PII. We hold the certifications, sign the DPAs, and architect the system to make that trust deserved.

SOC 2 Type IIFERPACOPPAGDPREducation Law § 2-dWCAG 2.2 AA
Certifications & frameworks

What we hold, and what it covers.

SOC 2 Type II

Annual audit covering Security, Availability, and Confidentiality. Reports available on request under NDA.

FERPA aligned

Designated as a school official under § 99.31(a)(1). Education records processed only for the disclosed purpose.

COPPA compliant

We process student PII only on behalf of, and at the direction of, the school. No marketing, no profiling.

GDPR ready

Standard Contractual Clauses, EU data residency, and a designated EU representative.

NY Ed Law § 2-d

Annual privacy and security practices report submitted, including the prescribed bill-of-rights addendum.

Pen-tested annually

Independent application and infrastructure assessments. Summary letters available to procurement.

Engineering practices

How the system is built.

Encryption everywhere

AES-256 at rest, TLS 1.2+ in transit. Per-tenant data encryption keys with quarterly rotation.

SSO + SCIM

SAML SSO via Okta, Google, Azure AD, OneLogin. Just-in-time provisioning and full SCIM lifecycle.

Granular access

Role-based access on every resource. Audit logs for every read, write, and export — exported to your SIEM.

Region pinning

Choose US, EU, or your private VPC for processing and storage. We never replicate cross-region.

No training on your content

Customer data is never used to train any model — ours or a vendor's. Contractually guaranteed.

BYOK & private cloud

Bring your own KMS keys, or run the full processing pipeline inside your own AWS or GCP environment.

Data lifecycle

From upload to zeroize.

Every file your district sends us moves through the same four stages. Each one is auditable, region-pinned, and tenant-scoped.

  1. 01
    Upload

    Files arrive over TLS, encrypted in transit. Hashed and tagged with tenant + region metadata before storage.

  2. 02
    Process

    Processed in-region by a sandboxed runner. No file leaves your region; logs strip PII before retention.

  3. 03
    Deliver

    Remediated file written back to the source — Drive, Canvas, your bucket — with the original preserved alongside.

  4. 04
    Retain

    30-day default retention. Configurable per workspace, with a hard zeroize on delete (no soft-deletes).

Security questions? We've got answers.

Our team has been through procurement at every district size. Send your questionnaire — we usually return it the same day.