Compliance Frameworks
Evident's school privacy review is structured around the frameworks district legal, privacy, and IT teams expect to see during procurement:
- DPA/NDPA: Student privacy documentation
- FERPA: Family Educational Rights & Privacy Act
- COPPA: Children's Online Privacy Protection Act
- NIST-informed: Cybersecurity review structure
Documentation your district's legal, privacy, and IT teams can use to evaluate Evident for a pilot or school license.
Compliance Documents
These documents are available upon request for any school district evaluating or currently using Evident.
School Procurement Packet
Self-Serve School Review. A single packet covering security overview, privacy summary, DPA/NDPA information, subprocessors, retention/deletion, accessibility readiness, implementation FAQ, rostering options, and support contacts.
- Designed for privacy, IT, and school leadership review
- Links to DPA, security, accessibility, and school plan surfaces
- Cautious claims language for early procurement conversations
Annual Security & Privacy Assessment
SOC 2 Trust Services Criteria structure. An annual assessment of Evident's security controls, infrastructure, identity management, vulnerability management, and EdTech-specific privacy workflows (FERPA/COPPA). Includes our full subprocessor inventory, data classification matrix, and encryption standards. This assessment is structured to align with the SOC 2 Trust Services Criteria; it is Evident's own assessment and is not a third-party SOC 2 certification of Evident.
- SOC 2 TSC-aligned structure
- Full infrastructure & subprocessor inventory
- Vulnerability scanning & testing results
- FERPA/COPPA-related audit logging evidence
- Data retention & disposal documentation
Management's Assertion Letter
CEO-signed security & privacy attestation. Formal attestation from Evident's CEO summarizing security and privacy controls. Covers authorized use, security safeguards, regulatory documentation, data sovereignty, data minimization, and disposal protocols.
- CEO-signed on company letterhead
- Summarizes DPA/NDPA-aligned controls
- Attached as cover to the Security Assessment
- NIST-informed cybersecurity framework mapping
Incident Response Plan Summary
NIST-informed incident response process. Summary of Evident's written data breach response plan, provided for school privacy review. Covers our incident classification matrix, NIST-informed response process, 72-hour notification target, and post-incident review procedures.
- NIST-informed response structure
- 4-phase response process documented
- 72-hour LEA notification target
- Post-incident review & remediation process
- Annual tabletop exercise commitment
Data Processing Agreement (DPA)
DPA/NDPA documentation for school districts. Evident provides DPA/NDPA documentation for school privacy review, based on common student data privacy agreement structures. Review DPA information or contact us to discuss district-specific terms.
- DPA/NDPA documentation available for review
- Data elements documented
- Subprocessor list with all 7 vendors
- Data disposition workflow documented
- District-specific terms can be discussed
Security at a Glance
Key security metrics and controls that protect your student data.
- 520+ (Integration Tests): Run on every deployment
- AES-256 (Encryption at Rest): All student data
- TLS 1.3 (Encryption in Transit): Every connection
- 72hr (Breach Notification Target): Aligned to common DPA timelines
- 60 day (Data Disposition): On DPA termination
- RLS (Tenant Isolation): Database-level enforcement
How to Request Compliance Documents
- 1. Contact Us: Email us at your convenience or use the contact form. Include your district name, your role, and which documents you need.
- 2. Verification: We verify your identity as an authorized representative of the school district. For existing DPA partners, we respond within 2 business days.
- 3. Document Delivery: Documents are delivered via secure email. DPA/NDPA information and request paths are available on the DPA page. Assessment reports and the IRP Summary are provided within 5 business days.
Our 72-Hour Notification Commitment
In the event of a confirmed data breach involving Student Data, Evident will notify your district within 72 hours of confirmation, aligned to common DPA timelines.
Our notification includes:
- Provider identification and direct contact information
- Incident timeline with date of breach and date of discovery
- Plain-language description of what happened
- Specific Student Data elements affected (referencing Exhibit B)
- Identification of impacted individuals
- Corrective actions taken and ongoing remediation steps
Ready to Partner with Evident?
Start with the procurement packet, review DPA/NDPA documentation and security materials, then contact us for school-specific review needs.