Security & Compliance

Built for
institutional trust.

Clerion is architected for FERPA, SOC 2 Type 1 attested, and 1EdTech Data Privacy certified. Every artifact a vendor review asks for is either published on this site or available to your institution upon request.

SOC 2 Type 1 attested1EdTech Data Privacy certified1EdTech memberInstructure Integrated Tier PartnerSOC 2 Type 2 in progress

Read-only by design

The Canvas connection uses read-only scopes over OAuth 2.0. Clerion cannot create, edit, or delete anything in Canvas: syncs write to Clerion’s own database, never back to your LMS.

Metadata, not coursework

Clerion works from the course record: assignment names, due dates, weights, point values, and grades, together with the course text Canvas already shows the student, such as syllabi and announcements. It never reads or stores the contents of student work: no submissions, no essays, no coursework.

Independently tested. Independently certified.

Two third parties have examined how Clerion handles student data. Their findings are the badges below, and the reports behind them are available to your institution.

SOC 2 Type 1: tested and attested by Prescient Assurance
Complete

SOC 2 Type 1

Clerion’s security controls were tested and attested by Prescient Assurance. A SOC 2 Type 2 examination, which observes those same controls operating over a period of time, is in progress.

Request the report under NDA
1EdTech TrustEd Apps Certified: Data Privacy
Certified

1EdTech TrustEd Apps: Data Privacy

Clerion’s privacy practices are certified against the 1EdTech Data Privacy Rubric, the framework institutions use to vet the apps they adopt. The policy that earned it is published in full, and Clerion is a 1EdTech member.

Read the privacy policy

What a vendor review asks for, and where it is.

Published documents are linked. Anything marked available upon request is sent to your institution’s security or compliance contact on request; email alex@clerionai.com with the school and the document you need.

Available upon request

HECVAT

The Higher Education Community Vendor Assessment Toolkit, the questionnaire most institutions use to evaluate cloud vendors. Clerion’s HECVAT is completed in full and sent to institutions on request.

Request HECVAT
Available upon request

FERPA one-pager

Clerion is architected for FERPA and operates as a school official: education records are read only through your school’s Canvas, only with your school’s approval, and used only for legitimate educational purposes, powering the student’s own view. Student data is never sold. The one-pager walks through how, for your compliance office.

Request the FERPA one-pager
Type 1 complete

SOC 2 report

The SOC 2 Type 1 report, attested by Prescient Assurance, is shared with institutions under NDA. The Type 2 examination is in progress and its report will be shared the same way when issued.

Request under NDA
Published

Privacy Policy

What Clerion collects, how it reaches us, what it is used for, how long it is kept, and how it is deleted. Written to the 1EdTech Data Privacy Rubric, with a change record for every revision.

Read the policy
Published

Terms of Service

The terms governing use of Clerion by students and partner institutions.

Read the terms
Published

Subprocessors

The complete list of third parties that process data in operating Clerion, what each one does, exactly what data it receives, and where. Kept in the privacy policy so there is one list, not two.

View the list
Published

Accessibility statement and VPAT

Where Clerion stands against WCAG 2.1 Level AA, what works today, and known limitations. The Accessibility Conformance Report (VPAT® 2.5Rev, Revised Section 508) is available upon request.

Read the statement
Published

Incident notification

In the event of a confirmed breach affecting personal data, the affected people and their institution are notified without undue delay and no later than 72 hours after confirmation. Notification is not deferred pending the investigation.

Read the commitment

The controls behind the badges.

Each of these is a control we maintain, test, and enforce through automated gates rather than procedure alone. The full description is in the privacy policy.

No passwords on our servers

Sign-in is delegated to WorkOS, our identity provider: institutional single sign-on over SAML or OIDC, so your MFA policy applies automatically. Passwords, where used, live at WorkOS, never on Clerion’s servers. LTI launch from Canvas is also supported.

Encrypted in transit and at rest

Every connection, browser to server, server to Canvas, and server to database, uses TLS 1.2 or later with HSTS. Database contents, backups, and logs are encrypted at rest with AES-256.

Isolation enforced in the database

Each institution’s data is isolated by row-level security policies in PostgreSQL, so a query scoped to one school cannot return another’s records. An automated test verifies this on every change.

Least privilege, fully audited

The application connects with a restricted database role, production access is limited to authorised personnel, and every access to an academic record is written to an append-only audit log.

AI reads. It never decides.

Personal identifiers are removed before any text reaches our AI provider, and that content is not used to train models. Grade math is computed from the course’s real grading rules; AI never invents a number.

Read-only in Canvas

Clerion’s Canvas connection is limited to read-only scopes: it cannot create, edit, or delete anything in Canvas, so even a compromise of Clerion could not alter grades or submissions held there.

Hosted in the United States

The application, database, and secret store run on Google Cloud in the United States. Credentials and API keys live in a managed secret store, never in source code, configuration, or logs.

Deleted or returned in 30 days

On termination of an institutional agreement, institutional data is deleted or returned within 30 days, at the institution’s election. Deleted data leaves encrypted backups as they expire, within 30 days.

Secure development, gated

Every change passes automated type, lint, architecture, and test gates together with dependency vulnerability scanning before release, and is reviewed prior to merge.

The full text of these controls, including cookies, sessions, and staff access, is in the privacy policy under How data is protected and Accounts, sign-in, and passwords.

Have questions?

Ask about anything on this page, send a security questionnaire, or request a document. Include your institution and we’ll take it from there. Or write directly to alex@clerionai.com.

Email the team