SOC 2 Type 1
Clerion’s security controls were tested and attested by Prescient Assurance. A SOC 2 Type 2 examination, which observes those same controls operating over a period of time, is in progress.
Request the report under NDAClerion is architected for FERPA, SOC 2 Type 1 attested, and 1EdTech Data Privacy certified. Every artifact a vendor review asks for is either published on this site or available to your institution upon request.
SOC 2 Type 1 attested1EdTech Data Privacy certified1EdTech memberInstructure Integrated Tier PartnerSOC 2 Type 2 in progress
The Canvas connection uses read-only scopes over OAuth 2.0. Clerion cannot create, edit, or delete anything in Canvas: syncs write to Clerion’s own database, never back to your LMS.
Clerion works from the course record: assignment names, due dates, weights, point values, and grades, together with the course text Canvas already shows the student, such as syllabi and announcements. It never reads or stores the contents of student work: no submissions, no essays, no coursework.
Two third parties have examined how Clerion handles student data. Their findings are the badges below, and the reports behind them are available to your institution.
Clerion’s security controls were tested and attested by Prescient Assurance. A SOC 2 Type 2 examination, which observes those same controls operating over a period of time, is in progress.
Request the report under NDA
Clerion’s privacy practices are certified against the 1EdTech Data Privacy Rubric, the framework institutions use to vet the apps they adopt. The policy that earned it is published in full, and Clerion is a 1EdTech member.
Read the privacy policyPublished documents are linked. Anything marked available upon request is sent to your institution’s security or compliance contact on request; email alex@clerionai.com with the school and the document you need.
The Higher Education Community Vendor Assessment Toolkit, the questionnaire most institutions use to evaluate cloud vendors. Clerion’s HECVAT is completed in full and sent to institutions on request.
Request HECVATClerion is architected for FERPA and operates as a school official: education records are read only through your school’s Canvas, only with your school’s approval, and used only for legitimate educational purposes, powering the student’s own view. Student data is never sold. The one-pager walks through how, for your compliance office.
Request the FERPA one-pagerThe SOC 2 Type 1 report, attested by Prescient Assurance, is shared with institutions under NDA. The Type 2 examination is in progress and its report will be shared the same way when issued.
Request under NDAWhat Clerion collects, how it reaches us, what it is used for, how long it is kept, and how it is deleted. Written to the 1EdTech Data Privacy Rubric, with a change record for every revision.
Read the policyThe terms governing use of Clerion by students and partner institutions.
Read the termsThe complete list of third parties that process data in operating Clerion, what each one does, exactly what data it receives, and where. Kept in the privacy policy so there is one list, not two.
View the listWhere Clerion stands against WCAG 2.1 Level AA, what works today, and known limitations. The Accessibility Conformance Report (VPAT® 2.5Rev, Revised Section 508) is available upon request.
Read the statementIn the event of a confirmed breach affecting personal data, the affected people and their institution are notified without undue delay and no later than 72 hours after confirmation. Notification is not deferred pending the investigation.
Read the commitmentEach of these is a control we maintain, test, and enforce through automated gates rather than procedure alone. The full description is in the privacy policy.
Sign-in is delegated to WorkOS, our identity provider: institutional single sign-on over SAML or OIDC, so your MFA policy applies automatically. Passwords, where used, live at WorkOS, never on Clerion’s servers. LTI launch from Canvas is also supported.
Every connection, browser to server, server to Canvas, and server to database, uses TLS 1.2 or later with HSTS. Database contents, backups, and logs are encrypted at rest with AES-256.
Each institution’s data is isolated by row-level security policies in PostgreSQL, so a query scoped to one school cannot return another’s records. An automated test verifies this on every change.
The application connects with a restricted database role, production access is limited to authorised personnel, and every access to an academic record is written to an append-only audit log.
Personal identifiers are removed before any text reaches our AI provider, and that content is not used to train models. Grade math is computed from the course’s real grading rules; AI never invents a number.
Clerion’s Canvas connection is limited to read-only scopes: it cannot create, edit, or delete anything in Canvas, so even a compromise of Clerion could not alter grades or submissions held there.
The application, database, and secret store run on Google Cloud in the United States. Credentials and API keys live in a managed secret store, never in source code, configuration, or logs.
On termination of an institutional agreement, institutional data is deleted or returned within 30 days, at the institution’s election. Deleted data leaves encrypted backups as they expire, within 30 days.
Every change passes automated type, lint, architecture, and test gates together with dependency vulnerability scanning before release, and is reviewed prior to merge.
The full text of these controls, including cookies, sessions, and staff access, is in the privacy policy under How data is protected and Accounts, sign-in, and passwords.
Ask about anything on this page, send a security questionnaire, or request a document. Include your institution and we’ll take it from there. Or write directly to alex@clerionai.com.