This document is provided for informational purposes during our pre-launch period. A comprehensive, attorney-reviewed version will be published prior to the platform processing student data.

SECURITY TRUST CENTER

The SPEDScribe
Security Trust Center

Built for the most sensitive data in education.

DATA FLOW

Interactive Data Flow Diagram

Click any pipeline node to see exactly what happens at that stage.

COMPLIANCE

Compliance Controls

The legal foundations governing how we handle student education records. Click any card to expand.

FERPA
School Official Designation
Compliant

Operating under 34 CFR 99.31(a)(1) as a school official.

COPPA
School Official Exception
Compliant

School consent under the school official exception. No direct collection from children.

CCPA
No Sale or Commercial Profiling
Compliant

Student data is never sold and never used for commercial profiling.

SOPIPA
Student Online Personal Information Protection Act
Compliant

No advertising, no sale, no commercial student profiles.

AB 1584
California Education Code 49073.1
Compliant

District owns student data. 90-day deletion. 30-day subprocessor notice.

HIPAA-grade
BAA-Ready, PHI Handling Protocols
Voluntary

BAA available. PHI handling protocols aligned to HIPAA Security Rule.

TRUST BADGES

Certifications & Memberships

In Progress
SOC 2 Type I
Targeted Q3 2026
Verified
FERPA Compliant
School Official Designation
Active
SDPC Premium Member
Student Data Privacy Consortium
Certified
Clever Certified
SSO integration verified
Certified
ClassLink Certified
SSO integration verified

TECHNICAL CONTROLS

Technical Controls

Six layers of protection applied to every byte of student data.

AES-256
Encryption at Rest

All data stored on SPEDScribe infrastructure is encrypted using AES-256 with keys managed under a dedicated key management service.

TLS 1.3
Encryption in Transit

All data transmitted between users, our servers, and AI processing partners uses TLS 1.3, the current cryptographic standard.

Dual-Layer PII Redaction
Two Independent Passes

Every transcript passes through two independent PII scrubbing layers before reaching AI processing. See the Dual-Layer PII Pipeline section below for technical detail.

RBAC
Role-Based Access Control

Providers access only their own session data. Directors see only their district. Admins are separated from production student data.

SSO / SAML 2.0
Clever, ClassLink, Google

Districts can enforce SSO authentication through Clever, ClassLink, or Google Workspace. No separate credentials for providers to manage.

Zero AI Data Retention
Enforced by Contract

All AI processing partners execute zero-data-retention agreements. Student data is processed and immediately discarded — never stored by AI systems.

PII PIPELINE

Dual-Layer PII Scrubbing Pipeline

Two independent PII redaction passes ensure student identifiers never reach the AI model. Every session records exactly how many identifiers each layer caught.

INPUT
Voice Recording (on device)
1
Layer 1 — AssemblyAI PII Redaction
At transcription time (speech-to-text)

AssemblyAI's ML-based PII detection runs during transcription. Trained on millions of audio samples, it identifies and replaces person names, dates of birth, phone numbers, email addresses, SSNs, healthcare numbers, locations, and organizations directly in the speech-to-text output.

2
Layer 2 — Presidio-Inspired Pattern Scrubber
Server-side, before AI processing (self-hosted, Node.js)

A second, independent pass runs server-side on SPEDScribe infrastructure. Microsoft Presidio ships as a Python-only library, so we implement the equivalent detector design natively in Node.js: seven parallel pattern-matching detectors cover person names (via title-prefix, context, possessive, and speaker-label triggers), SSNs, phone numbers, email addresses, physical addresses, dates of birth (context-keyword windowed), and student ID numbers. A clinical allowlist of 40+ assessment tools and therapy methods (CELF, GFTA, WISC, Lindamood, Orton-Gillingham, etc.) prevents false positives on legitimate clinical terminology.

[PERSON][SSN][PHONE][EMAIL][ADDRESS][DOB][STUDENT_ID]
OUTPUT
De-identified transcript reaches AI model
Auditable Metadata

Every session records the count of PII entities caught by each layer and which categories were detected. Districts can audit exactly what was scrubbed and when.

Graceful Degradation

If Layer 2 encounters an error, the system proceeds with Layer 1 protection only and flags the session as "single-layer-only" so it can be reviewed.

Clinical Accuracy

A curated allowlist of 80+ assessment tools, clinical terms, and therapy method names ensures the scrubber never removes legitimate clinical vocabulary from transcripts.

RESOURCES

Security Resources

Documentation and tools for district IT teams conducting vendor security reviews.

📄
Security Questionnaire

Pre-filled responses to the 10 most common district IT security questions. Download a print-ready PDF for your vendor review process.

🛡
Penetration Testing

Independent third-party penetration testing of all SPEDScribe infrastructure and application layers. Results available to districts under NDA.

Scheduled Q3 2026
📜
FERPA Attestation

Our full FERPA compliance statement, including school official designation under 34 CFR 99.31(a)(1) and student data rights documentation.

View FERPA Statement →

AI TRANSPARENCY

AI Transparency

Our Clinical Intelligence Engine processes de-identified transcripts only. Student names, dates of birth, ID numbers, and other identifiers are removed through a dual-layer PII scrubbing pipeline before any transcript reaches the AI model. Layer 1 (AssemblyAI) operates at transcription time with ML-based detection. Layer 2 is a SPEDScribe pattern-matching scrubber modeled on Microsoft Presidio's detector design, running seven parallel regex detectors with a clinical allowlist that protects assessment terminology. Both layers log metadata so districts can audit exactly what was caught. All AI processing partners execute zero-data-retention agreements. Student data is never used to train AI models. Every AI-generated document requires human review and approval before filing.

INFRASTRUCTURE

Infrastructure

SOC 2 Type II
In Progress

Targeted Q1 2027

ISO 27001
Aligned Partners

Infrastructure providers are ISO 27001 certified

Encrypted Data Vault
AES-256

All stored data encrypted with dedicated key management

Automated Backup
Disaster Recovery

Continuous backup with point-in-time recovery capability

ROADMAP

Certifications Roadmap

SDPC Premium Vendor Signatory
CompleteQ2 2026
SOC 2 Type I
In ProgressQ3 2026
SOC 2 Type II
PlannedQ1 2027
iKeepSafe FERPA Certification
In ProgressQ4 2026
SDPC Resource Registry Enrollment
In ProgressQ2 2026

INCIDENT RESPONSE

Incident Response

Dedicated Security Team

A dedicated security contact is available at all times for incident triage and response.

FERPA Breach Notification

Breach notification provided without unreasonable delay as required by FERPA.

72-Hour District Notice

Written notification to affected districts within 72 hours of confirmed breach discovery.

Root Cause Analysis

Written root cause analysis and remediation report provided to affected districts within 30 days.

CONTACT

Security Contact

To report a security vulnerability, request a security assessment, or ask questions about our compliance posture:

security@spedscribe.ai