Skip to main content

Security at ClassLens

Built so districts can say yes.

SOC 2 Type I attested. Google CASA Tier 2 verified. Federal CISA Secure by Design Pledge signatory. Google-approved Zero Data Retention on our Vertex AI project. Student work is processed transiently, and ClassLens keeps no copy of student files for review.

SOC 2 Type I attestation badgeGoogle CASA Tier 2 security assessment badge

Audited by Percilchofe CPA LLC (License No. 1188). Report dated April 4, 2026, available under NDA. Most ed-tech vendors won’t name their auditor.

What districts ask us first.

Where does student work live?

Inside Google Classroom, where your teachers already keep it. Submissions transit our infrastructure long enough to be graded: each file is staged in a private Google Cloud Storage bucket for AI processing and best-effort deleted afterwards, with a 24-hour bucket lifecycle policy as the failsafe. While the job runs, submission metadata and per-student results sit in an encrypted Redis job cache. It is cleared once the job finishes successfully; a job that ends incomplete keeps its cache so the work is recoverable, and either way the 48-hour expiry is the outer bound. In Grade & Review mode, ClassLens keeps the drafted results for teacher review, with each student's name and email address and the names, links and version details of their files. It does not keep a copy of the submission files: the review screen loads each file in the teacher's browser directly from Google Drive. This review copy is deleted when the teacher releases the grades or keeps them as drafts, with a 24-hour expiry as the failsafe. In Draft Only mode, a separate read-only copy of student display names, submission identifiers, scores, criterion results and generated feedback is available to the teacher who ran the job for up to 24 hours from the start of the job. Account deletion removes access to the Draft Only copy and attempts to delete it; if that deletion fails, the copy still expires on its own 24 hours from the start of the job. Opening it does not extend the window, and returning grades in Google Classroom does not delete it. It contains no separate student email-address field, submission files or attachment links. Generated feedback may itself include a student's name or details from their work. Sheet Export jobs do not create either teacher-review copy. The encrypted job-processing cache retains its separate 48-hour expiry failsafe. Email, provider caches and recipient mailboxes follow the separate retention periods in Section 7 of the Privacy Policy. The draft grade itself is written to Classroom during grading, not afterwards. Once a job’s results are released or expire, ClassLens deletes the student submission content, grades and AI-generated feedback it held; the staging delete is best-effort, and a bucket rule automatically deletes anything left after 1 day, typically within 48 hours.

Read the full FERPA posture →

Who has reviewed your security?

A licensed CPA firm (Percilchofe CPA LLC, License No. 1188) issued an unqualified SOC 2 Type I opinion as of April 4, 2026. Google’s CASA Tier 2 assessment was completed by TAC Security on April 1, 2026. Google verified our OAuth scopes — including the restricted Drive scope — on April 9, 2026.

See attestations and dates →

Does Google use our data to train AI?

No. ClassLens runs on Google Cloud Vertex AI under the Cloud Data Processing Addendum, which contractually prohibits Google from using customer data to train its foundation models. Zero Data Retention is enrolled — Google has formally approved a no-prompt-logging exception for our Vertex AI project. We publish this here so districts do not have to ask.

See the data flow →

Attestations and verifications.

Names, dates, license numbers. No marketing adjectives.

SOC 2 Type I
SOC 2 Type I Attested by Percilchofe CPA LLC (License No. 1188); as of April 4, 2026; unqualified opinion. Full report available under NDA.
Socify Letter of Validation
Socify-issued Letter of Validation (April 27, 2026) confirming our control environment was evaluated against the applicable AICPA Trust Services Criteria and assessed for readiness for an independent SOC 2 audit. It is a readiness document, not the audit. Published openly so you can see something before signing anything; the SOC 2 Type I attestation report from Percilchofe CPA LLC is available under NDA.
Google CASA Tier 2
CASA Tier 2 security assessment complete (Letter of Validation submitted April 1, 2026 by TAC Security via the Google-authorized ESOF AppSec platform).
Google OAuth verification
Google OAuth verified (April 9, 2026), including the restricted Google Drive scope, gmail.send, and classroom.profile.emails.
CISA Secure by Design Pledge
Signed April 28, 2026, and listed on CISA’s public signer registry under our legal name, Evolved Academics (verified 2026-07-25). A voluntary commitment to seven security goals; CISA does not endorse or certify signatories.
FERPA posture
FERPA school-official posture under 34 CFR 99.31(a)(1)(i)(B); ClassLens temporarily stores student submissions and drafted grading results to process grading jobs and support teacher review. These application copies expire within 48 hours. Separate grading identifiers, opt-out records, and email-related records can remain longer, as described in Privacy Policy Section 7.
COPPA-aligned program
COPPA-aligned: Written Information Security Program (WISP v1.2), Data Retention Schedule, School Consent Framework v1.1, and Privacy Policy Section 7 with specific retention timeframes are deployed.
Model-training posture
Google Cloud Vertex AI under the Google Cloud Data Processing Addendum (CDPA) does not use submitted data to train Google’s foundation models. Zero Data Retention is enrolled — Google has formally approved a no-prompt-logging exception for our Vertex AI project.

What is the CISA Secure by Design Pledge?

CISA Secure by Design
Evolved Academics signed the CISA Secure by Design Pledge on April 28, 2026. Logo used with CISA’s written permission, granted August 17, 2026.

The Student Privacy Pledge — the badge many EdTech vendors displayed for a decade — was retired by the Future of Privacy Forum on April 25, 2025, after more than 40 states codified its principles into binding law. New signatories have not been accepted since that date, and the public registry of past signatories was taken offline July 31, 2025. ClassLens commits to the substantive Pledge principles in our Privacy Policy and Terms of Service.

At retirement, FPF pointed vendors toward two frameworks: the SDPC National Data Privacy Agreement (NDPA), which we have drafted vendor-side exhibits to execute, and CISA’s Secure by Design program. CISA runs two separate pledges under that program. The K-12 Education Technology Secure by Design Pledge was signed by a small group of major student information and learning management platforms. The broader CISA Secure by Design Pledge is open to all software makers and commits signers to seven concrete security goals, from multi-factor authentication to coordinated vulnerability disclosure; its registry lists hundreds of cybersecurity and technology companies. Evolved Academics signed the CISA Secure by Design Pledge on April 28, 2026. The live registry is published at cisa.gov/securebydesign/pledge/secure-design-pledge-signers.

Signing is a public, voluntary commitment, not a certification: CISA does not endorse signatories, audit them, or attest to the security of any product. We name it here because it is verifiable in one click, not because it is an award.

If your procurement rubric still asks for a Student Privacy Pledge badge, the honest industry answer is that pre-2025 signatories were grandfathered into a sunset program with no live registry, while ClassLens has aligned with the frameworks that replaced it.

See something before you sign anything.

Most vendors show you nothing until an NDA is countersigned. We publish the Socify Letter of Validation openly — a third-party confirmation that our control environment was evaluated against the applicable AICPA Trust Services Criteria and assessed for readiness for an independent SOC 2 audit. It is a readiness document, not the audit itself. The SOC 2 Type I attestation (Percilchofe CPA LLC, License No. 1188, unqualified opinion, as of April 4, 2026) is available under NDA.

Download the readiness Letter of Validation (PDF)

Issued April 27, 2026 by Socify. ~90 KB.

Need the full report? Request it under NDA.

Organization type

Please use your work email so we can verify the request.

What we do with this: we use the details above to verify your organization and send you the report under NDA. We also record the submitting IP address and browser user agent to protect the form from abuse. Our monthly purge erases the IP address and user agent from the request database once they are more than 90 days old, and deletes the request record itself once it is more than 12 months old; a copy of your request also reaches our internal security mailbox. We do not sell this information or use it for advertising. See our Privacy Policy for the full retention schedule.

Where student data lives — and where it does not.

ClassLens operates as a school official under FERPA 34 CFR 99.31(a)(1)(i)(B). The school or district directs us to perform a function (grading assistance) the district would otherwise perform itself, under the district’s direct control over the use and maintenance of education records.

ClassLens temporarily stores student submissions and drafted grading results to process grading jobs and support teacher review. These application copies expire within 48 hours. Separate grading identifiers, opt-out records, and email-related records can remain longer, as described in Privacy Policy Section 7. Where a teacher has feedback emailed, our email provider, Amazon SES, keeps addresses that bounce or draw a complaint on its suppression list until they are removed; Privacy Policy Section 7 lists those email records and the opaque grading and opt-out identifiers that can outlive a job. Submissions transit our infrastructure to be graded and the resulting drafts are written back to Google Classroom (the district’s system of record).

In Grade & Review mode, ClassLens keeps the drafted results for teacher review, with each student's name and email address and the names, links and version details of their files. It does not keep a copy of the submission files: the review screen loads each file in the teacher's browser directly from Google Drive. This review copy is deleted when the teacher releases the grades or keeps them as drafts, with a 24-hour expiry as the failsafe. In Draft Only mode, a separate read-only copy of student display names, submission identifiers, scores, criterion results and generated feedback is available to the teacher who ran the job for up to 24 hours from the start of the job. Account deletion removes access to the Draft Only copy and attempts to delete it; if that deletion fails, the copy still expires on its own 24 hours from the start of the job. Opening it does not extend the window, and returning grades in Google Classroom does not delete it. It contains no separate student email-address field, submission files or attachment links. Generated feedback may itself include a student's name or details from their work. Sheet Export jobs do not create either teacher-review copy. The encrypted job-processing cache retains its separate 48-hour expiry failsafe. Email, provider caches and recipient mailboxes follow the separate retention periods in Section 7 of the Privacy Policy.

ClassLens also retains limited records to support grading, billing, student opt-outs, and email delivery. These include:

  • Legacy grading-history records containing opaque student, course, and assignment identifiers, retained for up to 12 months.
  • A submission identifier retained for 90 days to support billing reconciliation and help prevent duplicate processing.
  • Student and class identifiers used to honor a student’s AI-grading opt-out, retained until 24 months after the opt-out was last used.
  • When feedback is emailed, an opaque delivery record retained for 48 hours.
  • After a bounce or complaint, a keyed suppression digest retained for 90 days.

These identifiers and digests may still be linked to a student or recipient. Privacy Policy Section 7 describes the retained records and their retention periods.

Google Cloud Vertex AI under the Cloud Data Processing Addendum does not use submitted data to train Google’s foundation models.

How a student submission moves through ClassLens.

Six steps. Plain English.

  1. 1A teacher signs in to ClassLens with Google. Only the OAuth scopes Google has verified are used.
  2. 2The teacher picks a Classroom assignment and configures grading preferences.
  3. 3ClassLens fetches the submission from Google Classroom using the teacher's authorized session.
  4. 4The submission, the student's name, and the teacher's rubric and assignment instructions are sent to Google Cloud Vertex AI for inference under the Cloud Data Processing Addendum; the submission file is staged in a private Google Cloud Storage bucket for that call. Submissions are not used to train Google’s foundation models, and Zero Data Retention is enrolled — Google has formally approved a no-prompt-logging exception for our Vertex AI project. ClassLens deletes the staged file from Cloud Storage immediately after grading; a 24-hour bucket lifecycle policy is the safety net.
  5. 5The draft grade is written to Google Classroom during grading in BOTH modes. In Draft Only that is the whole write-back; in Grade & Review the grade and its feedback are additionally routed to the in-app Batch Review Dashboard, and on release ClassLens marks the grade assigned in Classroom and delivers the feedback to the student.
  6. 6In both modes, submission metadata and per-student results sit in an encrypted job cache while the job runs; it is cleared once the job finishes successfully, a job that ends incomplete keeps its cache so the work is recoverable, and either way the 48-hour expiry is the outer bound. In Grade & Review mode, ClassLens keeps the drafted results for teacher review, with each student's name and email address and the names, links and version details of their files. It does not keep a copy of the submission files: the review screen loads each file in the teacher's browser directly from Google Drive. This review copy is deleted when the teacher releases the grades or keeps them as drafts, with a 24-hour expiry as the failsafe. In Draft Only mode, a separate read-only copy of student display names, submission identifiers, scores, criterion results and generated feedback is available to the teacher who ran the job for up to 24 hours from the start of the job. Account deletion removes access to the Draft Only copy and attempts to delete it; if that deletion fails, the copy still expires on its own 24 hours from the start of the job. Opening it does not extend the window, and returning grades in Google Classroom does not delete it. It contains no separate student email-address field, submission files or attachment links. Generated feedback may itself include a student's name or details from their work. Sheet Export jobs do not create either teacher-review copy. The encrypted job-processing cache retains its separate 48-hour expiry failsafe. Email, provider caches and recipient mailboxes follow the separate retention periods in Section 7 of the Privacy Policy.

Data processors and operational vendors.

Each vendor is labeled by role. Data processors handle customer personal data for us. Operational vendors support source-code hosting and monitoring; each row's data category shows what they receive. Privacy Policy Section 6 lists our personal-data processors.

VendorPurposeData CategoryRegion
Amazon Web Services (AWS)Data processorApplication hosting, MySQL, Redis, and Amazon SES company emailApplication data, operational metadata, email recipient addresses and message content including teacher-requested student feedback. SES suppression addresses remain until removed; Privacy Section 7 describes delivery records and mailbox copies.us-west-1 (N. California)
CloudflareData processorCDN, DDoS, TLS termination, WAFAll traffic between browsers and ClassLens in transit (TLS terminated at the edge); network metadataGlobal edge
Google LLCData processorOAuth, Classroom API, Drive API, Sheets APIAuthentication, assignment + grade write-backUS
Google Cloud PlatformData processorVertex AI inference, per-job prompt caching + Cloud Storage submission stagingSubmission content, and the student's first name from the class roster, sent only when the teacher has feedback comments turned on so the comment can address them by name; together with the teacher's rubric and assignment instructions (all transiently). The submission is sent as the student wrote it, so it may itself contain their name; we attach no other identifier. Cloud DPA. Project-level ZDR approved by Google 2026-04-30 (Cloud project 135589175772); this approval concerns prompt logging. Eligible jobs may cache shared assignment, rubric and grading context for up to five minutes, limited to that job. Google separately caches inference inputs, outputs and derived data in project-isolated memory with a 24-hour expiry. This memory cache is not stored at rest. See Privacy Policy Section 6.1 for scope and deletion details.Cloud Storage: us-central1. ClassLens uses Google Gemini models through Google's US multi-region Vertex AI endpoint for grading, rubric generation, and knowledge gap reports. Inference stays within the United States, rather than a single US region.
StripeData processorSubscription billingBilling identifiers, payment method tokensUS
Google Analytics 4Data processorServer-side conversion, public-demo and subscription-lifecycle eventsOpaque visitor identifier; plan and amount on a purchase event. No student data, no teacher name or email. No Google Ads account is linked to this property and we run no advertising campaigns, so nothing reaches Google AdsUS
Google Workspace (business email)Data processorClassLens's own transactional email: district invitations, district removal notices, contact-form, waitlist and report-request messages, operational alertsRecipient name and email address and the message content. The grading pipeline sends no student data here; a contact-form or report-request message reaches it as the sender typed itUS
GitHubOperational vendorSource code and internal documentation hostingApplication source and docs; not a store of student recordsUS
Healthchecks.ioOperational vendorDead man's switch for our monitoring and backup cronsHeartbeat pings against opaque check identifiers; no personal, student or application dataSee vendor

State student-data laws.

We adhere to the substantive privacy principles of state student-data laws including SOPIPA (California Bus. & Prof. Code 22584), AB 1584 (California Education Code 49073.1), and New York Education Law §2-d. State-specific attestations — including the New York §2-d Parents’ Bill of Rights and supplemental information disclosures — are issued upon district request as part of the contracting process. ClassLens additionally completes vendor security questionnaires for state and district frameworks (including Texas TX-RAMP-aligned questionnaires) on request. ClassLens is built on the SDPC National Data Privacy Agreement (NDPA) framework; vendor-side exhibits are drafted and ready to execute with an originating LEA, including the Exhibit E General Offer of Privacy Terms.

Engineering practices.

Encryption

All traffic is TLS 1.2 or higher in transit, terminated at Cloudflare. Application data at rest — including the MySQL data volume — sits on AWS EBS volumes encrypted with AWS KMS keys, and database backups are encrypted at rest in Amazon S3. OAuth tokens are encrypted at rest at the application layer with AES-256-GCM with a versioned key format.

Access

Production access is limited to the founder, gated by SSO and multi-factor authentication. AWS uses instance roles — no static keys. Inbound network access goes through a Cloudflare Tunnel; the AWS instance has no public inbound ports. Administrative actions are logged.

Incident response

Security incidents are handled per our Information Security Policy and our Written Information Security Program (WISP v1.2). Confirmed incidents involving district data trigger notification to the affected district within the timeframes specified in whatever data privacy agreement is in place with that district, and never later than 72 hours after confirmation.

Frequently asked.

Are you "SOC 2 certified"?
No vendor is. SOC 2 is an attestation, not a certification — the AICPA does not issue certificates for it. We hold a SOC 2 Type I attestation from Percilchofe CPA LLC, License No. 1188, as of April 4, 2026, with an unqualified opinion. Anyone who tells you they are “SOC 2 certified” is using imprecise language. We chose not to.
Why don’t you display the Student Privacy Pledge badge?
The Student Privacy Pledge was retired by the Future of Privacy Forum on April 25, 2025, after a decade in which more than 40 states codified its principles into binding law. New vendors have not been able to sign since that date, and the public signatory registry was taken offline July 31, 2025. We commit to the substantive Pledge principles in our Privacy Policy and Terms of Service. At retirement, FPF pointed vendors toward the SDPC National Data Privacy Agreement, which ClassLens is built on with vendor-side exhibits drafted, and toward CISA’s Secure by Design program. Evolved Academics signed the CISA Secure by Design Pledge on April 28, 2026.
Do you store student work?
ClassLens temporarily stores student submissions and drafted grading results to process grading jobs and support teacher review. These application copies expire within 48 hours. Separate grading identifiers, opt-out records, and email-related records can remain longer, as described in Privacy Policy Section 7. Where a teacher has feedback emailed, our email provider, Amazon SES, keeps addresses that bounce or draw a complaint on its suppression list until they are removed; Privacy Policy Section 7 lists those email records and the opaque grading and opt-out identifiers that can outlive a job. Submissions transit our infrastructure to be graded; the resulting drafts are written back to Google Classroom. The district’s Classroom remains the system of record.
Is ClassLens FERPA compliant?
FERPA does not offer a vendor “compliance” certification, so we describe our posture precisely. ClassLens operates as a school official under FERPA 34 CFR 99.31(a)(1)(i)(B) when a district authorizes it: the district directs us to perform grading assistance it would otherwise perform itself, under the district’s direct control over education records. ClassLens temporarily stores student submissions and drafted grading results to process grading jobs and support teacher review. These application copies expire within 48 hours. Separate grading identifiers, opt-out records, and email-related records can remain longer, as described in Privacy Policy Section 7. Where a teacher has feedback emailed, our email provider, Amazon SES, keeps addresses that bounce or draw a complaint on its suppression list until they are removed; Privacy Policy Section 7 lists those email records and the opaque grading and opt-out identifiers that can outlive a job. Google Classroom remains the system of record.
Is ClassLens COPPA compliant?
We describe ClassLens as COPPA-aligned rather than “certified,” because COPPA has no vendor certification. ClassLens is designed for teachers and authorized school staff. Students do not need a ClassLens account for their work to be graded. Sign-in does not check whether an account holder is a teacher, and an existing Classroom course is not required to explore ClassLens. The course list shows only Google Classroom courses where the signed-in account is a teacher. Student submissions transit our infrastructure for grading without being persistently retained on our servers. In Grade & Review mode, drafted results are held in a temporary review queue until the teacher releases or keeps the grades. If the teacher does not finish, the queue copy automatically expires after 24 hours. A separate encrypted job cache containing submission metadata and drafted results expires after 48 hours. These limits apply to the application’s grading copies. Separate identifiers, provider records, and copies delivered to email inboxes follow the retention practices described in Privacy Policy Section 7. ClassLens is built on the SDPC National Data Privacy Agreement framework and we will execute a district’s data privacy agreement.
Does Google use our submissions to train AI?
No. We use Google Cloud Vertex AI under the Cloud Data Processing Addendum, which contractually prohibits Google from using customer data to train its foundation models. Zero Data Retention is enrolled — Google has formally approved a no-prompt-logging exception for our Vertex AI project.
Can students see grades before our teachers approve them?
No. Auto-return was permanently removed from the product on April 12, 2026. Teachers either save grades as Classroom drafts (Draft Only mode) or review them in the in-app Batch Review Dashboard before releasing to students (Grade & Review mode).
Will you sign our NDPA?
Yes. ClassLens is built on the SDPC National Data Privacy Agreement framework and our vendor-side exhibits are drafted and ready to execute, including the Exhibit E General Offer of Privacy Terms that lets any subsequent district adopt the agreement without renegotiating. Email Steven directly and we will move on it the same week.

Contact.

Security questions, NDPA execution, and procurement: steven.swanson@evolvedacademics.com.

Responsible disclosure: report suspected vulnerabilities to security@evolvedacademics.com. Read our full responsible disclosure policy; machine-readable contact at /.well-known/security.txt.

Safe harbor: we will not pursue legal action against security researchers for activities conducted in good faith and consistent with our published policy. Specifically, we will not pursue claims under any of the following, including but not limited to: the federal Computer Fraud and Abuse Act (18 U.S.C. § 1030); the anti-circumvention provisions of the Digital Millennium Copyright Act (17 U.S.C. § 1201); the federal Stored Communications Act (18 U.S.C. § 2701 et seq.); California Penal Code § 502(c) and equivalent computer-misuse statutes in other U.S. states; or the federal Wiretap Act (18 U.S.C. § 2511) and equivalent state wiretap statutes, to the extent applicable. The list is illustrative and not exhaustive. We acknowledge reports within two business days and remediate per the SLAs in our incident management policy. We do not run a paid bounty program; we credit reporters who request it.

Last reviewed: 2026-09-05 • Evolved Academics, LLC • Whittier, CA